Admissibility memory for long-lived agents

Memory should preserve evidence—not inherit authority.

ProofToAct separates retrieval from authorization. Follow a three-act Highwater Drill in which evidence is admitted before ranking, one bounded decision is committed, and recovery returns context without power.

Run the proof Inspect evidence

3acts

11evidence checks

1authority boundary

Three-act judge path

Watch the authority boundary hold.

Use the controls or focus this section and press the arrow keys.

Highwater Drill

Loading the proof…

Loading proof…

Loading the proof.

Evidence ledger

Inspect the source behind each boundary.

Open the claims ledger

Live provider receipt

Check the provider path.

Run one bounded read from AWS Lambda through Managed MCP to CockroachDB.

01

Admit before ranking

Current, scoped, provenance-valid evidence enters retrieval. Expired, invalid, and out-of-scope records do not.

Inspect ambiguity evidence
02

Commit one outcome

Models may propose. A separate authority boundary decides which bounded operation receives a durable receipt.

Inspect authority evidence
03

Recover context, not power

A successor can recover signed context while the right to act remains absent until independently authorized.

Inspect recovery evidence

Trust architecture

Relevance can suggest. Only admissibility can authorize.

Evidence, authority, and recovery remain distinct.

ProofToAct trust boundaries: evidence is admitted before vector ranking; agents propose without authority; one fenced receipt is committed; recovery returns context only.

Invariant register

Every transition must preserve the boundary.

Open the register to inspect all eleven checks.

Loading checks… View every invariant

    Read the proof

    A synthetic crisis drill with inspectable source identity.

    The Highwater Drill uses synthetic emergency-response data to expose the difference between remembered evidence and permission to act. Follow the exact scenario, source identity, and file hashes below.