GOVERNED_ACT_MODEL.en.md

A manifesto for agentic systems

GOVERNED ACT MODEL

Intelligence creates possibilities. Power turns them into consequences.

The minimum form that separates what intelligence proposes from the power that produces consequences.

governed_surface

  1. 01 proposal
  2. 02 Mandate + Evidence
  3. 03 Act
  4. 04 world
  5. 05 Duty if unresolved
source
GOVERNED_ACT_MODEL.en.md
language
en
words
2826
reading
15 min

inspect forms --arity 4

The four forms

Four implementation-independent meanings make the boundary between conviction and consequence decidable.

01 / bounds

Mandate

Where the right to propose a consequence comes from.

02 / informs

Evidence

What we have reason to believe, without turning it into authority.

03 / records

Act

The recognised exercise of authority before capability is released.

04 / preserves

Duty

What the system does not yet have the right to call resolved.

cat GOVERNED_ACT_MODEL.en.md

Full text

v1 · immutable history

An agentic system is not governed because the agent is obedient, because its instructions are well written, or because someone tried to predict its every behaviour. An agent can be wrong, be persuaded, fabricate, change its plan, or produce faulty code. No architecture can make a mind—human or artificial—infallible.

The purpose of governance is not to prevent intelligence from thinking badly. It is to prevent intelligence from turning what it thinks into something that binds the world all by itself. The agent may propose freely, but a proposal must not contain the power required to realise itself. Between conviction and consequence there must be a separation that the agent does not control.

This separation matters because different things are continually confused. A convincing answer is not necessarily true. An authentic signature does not prove that the signer had authority. A working key makes action possible, but it does not make the action legitimate. Human approval is not valid if the person did not see what could have changed their decision. Knowledge, capability, and authority may meet, but none of the three must automatically become either of the others.

An agent is a delegate without loyalty: it does not create the power it spends, multiply it, inherit it from context, or duplicate it by copying itself; every move leaves a double-entry record that a stranger can verify again and that revocation does not erase; and whatever it has done without authority remains a debt to a human, suspending the power that produced it until someone ratifies or repudiates it.

Only four distinctions are needed to make this idea concrete.

A Mandate describes where the right to act comes from. It is the relationship through which someone grants someone else the ability to propose certain consequences, towards specified subjects and objects, for a purpose, within recognisable limits and conditions. It also says how long that right lasts and to whom what is done will be attributed.

A Mandate is neither a wish nor an instruction. “Help me with my company” may express an intention, but it does not establish which payments, data, messages, or decisions the agent may commit. The Mandate turns a general desire into a decidable boundary. If that boundary depends only on what the agent considers useful or reasonable, then the agent is still defining its own power.

Evidence describes what we have reason to believe. It may be a document, a signature, a reading of state, a receipt, testimony, an attestation, or the output of a model. It is not valid in the abstract: it is valid for the proposition it supports, and only while its provenance, freshness, and underlying assumptions remain valid.

Evidence informs a decision, but does not authorise it. A receipt may prove that a payment happened, not that ordering it was lawful. A model may identify a risk, not grant the right to ignore it. A message may contain an authentic request, but the request’s authority must come from elsewhere. Treating information as power is the simplest way for hostile content to become a command.

An Act describes what the system has actually decided to make possible. It is not the agent’s reasoning, not its proposal, and not yet the outcome in the world. It is the recorded and recognised exercise of authority that freezes a governed consequence: what will be attempted, by whom, on whose behalf, towards whom, with what data, under which Mandate, on the basis of which Evidence, and consuming which resources.

Before this decision is recorded as the system’s official truth, there is only a candidate. Afterwards, there is an Act. Only then may the system give an executor the concrete capability to attempt it. The world may answer with success, failure, or silence; none of those responses retroactively changes what was authorised.

A Duty describes what the system does not yet have the right to call resolved. It arises when authority, reality, and Evidence do not align. There may be an effect whose outcome is unknown, a promise left open, an intervention carried out beyond the Mandate, disputed Evidence, or repudiated responsibility.

A Duty is not merely an error to correct. It is normative memory. It preserves the cause, the subjects affected, what we know, what is missing, and the conditions capable of closing the case. It prevents a restart, a deadline, or someone’s silence from making something merely forgotten appear resolved.

The four forms therefore answer four different questions. The Mandate says what power exists. Evidence says what reality we can recognise. The Act says which exercise of that power has been recorded and recognised. The Duty says what distance between power, reality, and responsibility remains open. They prescribe no implementation: they are meanings that can be preserved in any language and any architecture.

Imagine that a person grants an agent the right to propose refunds of up to one hundred euros for orders that were genuinely paid. That delegation is the Mandate. The customer’s identity, the order, and proof of payment are Evidence. The agent proposes a fifty-euro refund, but the proposal moves no money. The system compares the amount, recipient, purpose, and Evidence with the Mandate. If it recognises them, it records an Act describing exactly that refund and only then makes the capability to contact the payment system available to the executor.

If a reliable receipt arrives, it becomes new Evidence about what happened and allows the system to record a closing decision. If instead the connection drops after submission and we do not know whether the money was sent, the system does not turn the absence of a response into failure and does not automatically try again. It opens a Duty. That Duty may be closed by reliable Evidence, reconciliation, or an authorised decision about how to bear the loss. It cannot disappear merely because it is inconvenient.

This small example already contains the entire model. The same relationships apply when an agent sends a message, publishes, reads a secret, uses a model, reserves a resource, delegates to another agent, changes a rule, or presents a person with a choice to approve.

Mediate everything that matters.

“Everything” does not mean every computation performed by the machine. An agent may reason, simulate, and generate hypotheses without asking permission at every step. It means every transition that the system wants to declare governed: an external effect, access to protected data, consumption, delegation, a commitment, or a presentation used to obtain consent.

Before governing, we must therefore say what matters. This declaration forms the governed surface. Between proposals and that surface lies a boundary that recognises Mandate and Evidence, decides, and records before allowing the consequence. The boundary may be a single component or a composition of isolation, consent, and recording. What matters is that it be singular from the standpoint of power: different paths must not be able to obtain the same consequence while avoiding the same official decision.

If the agent directly possesses a key capable of producing the effect, the boundary can be bypassed. If an administrator can change a rule without leaving an Act, governance does not govern itself. If a second path writes the same state without recognising the official decision, that truth has two owners. In all these cases, adding more logs is not enough: the side door must be closed, or that consequence must be admitted as ungoverned.

The same law applies to information. Protected data does not lose its constraints merely because it is summarised, transformed, or passed through a model. A derivative retains the constraints of the sources that may have influenced it. When we cannot know precisely which sources contributed, we can promise protection only by making a conservative declaration. Removing a constraint is itself a governed consequence and requires the authority of whoever owns that constraint.

Even asking for consent can be an exercise of power. If a person authorises on the basis of a presentation, that presentation must preserve what was materially relevant to the decision. Changing the recipient, data, cost, purpose, risk, or alternatives does not permit the old approval to be reused. Consent is not the gesture of pressing a button; it is the verifiable link between what was shown and what will be done.

Authority does not grow.

A technical capability says that something can happen. A Mandate says that someone has the right to propose it. Possessing the capability does not create that right. Knowing a password, finding a credential, receiving a message, or being called by a more powerful system does not enlarge authority.

Every delegation can only preserve or restrict the power from which it derives. The delegate may receive fewer operations, fewer recipients, less time, fewer resources, or stronger conditions. It cannot receive more than the delegator had the right to grant. Creating new power requires a new Act from an authority that already possesses it.

Nor does copying multiply power. Starting one hundred agents does not create one hundred times the budget, one hundred opportunities for approval, or one hundred identities. Copies and sub-agents share the limit from which they derive. When a portion is delegated, it cannot remain simultaneously spendable by the parent. Otherwise delegation would become a machine for minting authority.

Every Act must also distinguish who proposes, who executes, who authorises, and to whom the consequence is attributed. These positions may coincide, but they cannot be invented after an incident. Software does not become morally responsible because it executed code. If the system exposed a path without a Mandate, the Duty falls on the human or institutional chain that created, approved, or maintained that path.

Even the first authority must be named. No system can authorise its own birth from within. There is always a genesis recognised outside the model: the initial people, identities, rules, and procedures from which the chain begins. Honesty does not consist in pretending this trust has been eliminated, but in making it visible and preventing it from multiplying in secret.

An emergency must not become a secret sovereignty. An extraordinary path remains governed only if it has an explicit, limited, temporary, visible Mandate and cannot change the conditions of its own exception. If absolute access exists outside the model, that is the system’s true boundary, whatever the rest may promise.

Causality cannot be rewritten.

Every Act leaves a double-entry record. On one side remains the reason the intervention was permitted: the Mandate, the Evidence, the decision, and the conditions at that moment. On the other accumulates what the world returned: attempts, receipts, outcomes, contradictions, and uncertainty. The two sides are connected, but they do not replace one another.

The decision must be recorded before the capability to act is released. This order prevents the system from producing the effect first and constructing a justification afterwards. First power is recognised, then recorded, then delivered, and finally observed.

The external world is not atomic with the record. A payment may be executed while the network loses the response. A message may be received without a confirmation returning. At that moment the honest truth is “we do not know.” Uncertainty is not an elegant form of failure, and it does not automatically permit another attempt. Retrying could duplicate precisely the effect we cannot observe.

Revocation changes what may happen next, not what has already happened. It may stop a delivery that has not yet begun or prevent a new interpretation, but it cannot erase a real effect. A late receipt must remain recordable even if the old Mandate is no longer active, because recording the past does not reactivate its power.

Data deletion must also respect this distinction. Privacy protection may require removing content that must no longer be retained. It must not, however, fabricate a different causality. If deletion leaves part of the history unverifiable, the system preserves at least the fact that this capacity for verification was reduced.

When two systems meet, neither automatically inherits the other’s authority. The first records its own Act; the second receives a proposal and evaluates it under its own Mandate. They may exchange Evidence, but each is accountable for its own boundary.

Duty does not extinguish itself.

A Duty remains open until something happens that truly had the right to close it. A restart is not a solution. A new version is not a solution. A timer expiring does not prove that an effect did not occur. A person’s silence is not ratification.

Time may trigger a disposition that was already provided for, but that disposition must also be recorded as a new Act. A Duty may close because new Evidence satisfies a condition established before the problem, or because someone with the necessary authority decides how to ratify, repudiate, compensate, assign, or accept the loss.

Whoever produced the problem may bring Evidence, but must not be the sole judge of a discretionary decision that releases them from their own violation or removes another’s protection. Where this conflict exists, closure requires an independent authority. Independence does not necessarily mean different software or a different organisation; it means that the power to close does not derive from the interest that benefits from closure.

Ratification does not make retroactively authorised what was not authorised. Repudiation does not make what happened disappear. Compensation does not turn a loss into the absence of loss. Every disposition changes the present while preserving the cause that made it necessary.

From these four laws emerges a very simple machine. Intelligence produces a proposal. The system makes it precise enough to compare with Mandate, Evidence, constraints, and resources. It decides whether authority to proceed exists. It records the decision before releasing the capability. It observes the world separately. If promise and reality align, it closes the case; if they do not align or cannot be compared, it preserves a Duty.

A refusal is not a missing Act. It is a decision that says the candidate must not become an Act. Doubt, too, must remain distinct from prohibition: “I cannot determine it” does not mean “it is forbidden,” just as “this proposal is outside my vocabulary” does not mean “I evaluated and rejected it.” Confusing these outcomes allows an error or a gap to masquerade as governance.

The model does not promise that the world will cooperate, nor does it claim to control what the system does not own. An honest promise must state which consequences it includes, which paths it controls, and which assumptions it depends on. It must then distinguish narrative from protection. A record proves what passed through the boundary, but does not by itself prove that no other doors existed. Isolation may prevent a bypass, but does not by itself prove that the rules were correct. Tests, attestations, and independent review increase confidence in these properties without turning it into absolute certainty.

This limit does not weaken the model. It prevents the model from lying. The Governed Act Model does not promise that the agent tells the truth, that the code is free of errors, that every alternative was considered, or that every effect is reversible. It promises something more precise: within the declared perimeter, a proposal does not create authority on its own, Evidence does not become a right, a capability does not become a Mandate, the present does not silently alter the cause of the past, and whoever produced a debt cannot erase it for convenience.

To understand whether a new capability belongs within the model, there is no need to add a new constitution. It is enough to ask whether it can be bounded by a Mandate, supported by Evidence, recorded as an Act before receiving the power to act, and transformed into a Duty when reality and promise do not align. If it requires a second source of authority, a side door to the same consequence, or a form able to absolve itself, it is not extending the model: it is bypassing it.

Governing an agent does not mean teaching it to be good. It means preventing its conviction from becoming power on its own. Intelligence proposes. The Mandate bounds. Evidence informs. The Act records an exercise of authority. The world responds. The Duty preserves what the system does not yet have the right to call resolved. And governance passes through the same laws it applies.

An agent is a delegate without loyalty: it does not create the power it spends, multiply it, inherit it from context, or duplicate it by copying itself; every move leaves a double-entry record that a stranger can verify again and that revocation does not erase; and whatever it has done without authority remains a debt to a human, suspending the power that produced it until someone ratifies or repudiates it.

This is not a theory about how an agent should think. It is the minimum form that allows a system to state, without lying, that intelligence acted under governance.