Appendix C: Witness Protocol

Type: kb/articles/types/article.md ยท Status: draft

This appendix is the canonical statement of the witness protocol. The list in the body is its summary.

Summary from the body

  1. Holding and application. Given adequate project-specific state, the house sustains theory-guided proposal, evaluation, diagnosis, or recovery across novel changes, including cases whose correct handling is not stated verbatim in that state. With everything else held equal, withholding or replacing the relevant state changes what the house does next in a predicted way.
  2. Initial acquisition. From permitted records, interaction, and participation in the work, the house acquires the capacity an adequate program theory provides instead of receiving the decisive project-specific understanding from a human. The theory may be written down, reliably reconstructed from records each time, or a mix.
  3. Successor acquisition. When experience exposes an inadequacy, the house reaches a successor state that supports coherent later modification. An example is a dependency change that makes an earlier design reason false. The revision may touch explicit theory, records, software, production machinery, or a combination.
  4. Automated continuation. The house sustains these capacities across the declared scope and horizon with no human in an internal role.

Canonical full statement

One witness run must demonstrate the whole progression under one declared regime. Before interpreting results, it records the product scope, operating horizon, compute/time/cost budget, seed state, mutable state, update and retention machinery, context assembly, evaluators, safety boundaries, and every permitted external input. It pins every eligible LLM version available by 2026-09-02, all model weights, and every other learned component such as an embedding model. A derived index may change only as a mechanical view regenerated by pinned declared machinery from mutable notes and code.

The request process is fixed before the run. The declaration distinguishes the admissible request-and-consequence histories, the history realized in a run, and the probability distribution or selection procedure over histories. It must be capable of relevant novelty rather than replaying a fixed task list. These objects, the product scope, the horizon, and the budget may not be changed after a failure is observed. The witness must state what usable hitting probability within budget and what continuation reliability across the horizon count as practical; one lucky reachable path is insufficient.

The mutable house state includes its natural-language and symbolic artifacts: product code, notes, schemas, tests, tools, production rules, evaluators, retention rules, and machinery that selects context or updates the house. A successor may revise any eligible surface, including the update machinery itself, but it must arise from the predecessor state's computational machinery and the permitted external inputs. A human correction during bootstrapping is exogenous to the autonomous lineage. Seed tools, interfaces, safeguards, and provisional theory are allowed, but their existence is seed engineering rather than evidence that the house acquired the decisive project-specific capacity.

Users remain external when they supply product-level requirements, domain facts, observed outcomes, or acceptance judgments about visible behaviour. A person occupies an excluded internal role when the house depends on that person to diagnose an implementation or theory failure, compare internal candidates, edit decisive project theory, choose a retained successor, repair required production machinery, or otherwise perform production work. During a witness run, a newer model also may not supply trial-specific theory, diagnose internal failures, select successors, or fill any other excluded internal role.

The obligations are then applied as follows:

  1. Holding and application requires theory-guided proposal, evaluation, diagnosis, or recovery across novel modifications, including implications not stated verbatim in retained state. The theory may be explicit, reconstructed reliably from records, or mixed. With all else held equal, withholding or replacing the relevant state must alter later behaviour in a predicted way. Search, backtracking, a record naming the theory consumed at decision time, or one successful change does not suffice unless project-specific state causally shapes the path.
  2. Initial acquisition requires computation to acquire the program-specific capacity from permitted records, interaction, and participation rather than receive decisive understanding from a human. The learned result must outgrow repeated human authorship of task-specific theory and must change how the house handles a later job it had not yet received. Carrying forward only the product state requested by the earlier job does not establish acquisition.
  3. Successor acquisition requires computation to use later experience to reach and retain a replacement state when earlier theory, software, or machinery becomes inadequate. The successor must support coherent later modification. Storing or paraphrasing a rationale does not suffice unless it governs a later decision; a gate that rejects a bad candidate does not suffice unless the admitted successor is adequate. A retained note never loaded by the production path does no work for this obligation.
  4. Automated continuation requires the first three capacities to continue across the declared product scope and operating horizon with no human in an internal role. If the scope exposes a need to change production machinery, the house must make that change through an allowed successor transition. Fixed general machinery may remain only while it remains adequate for the declared scope.

Obligations 2 and 3 must be produced by computation; this is a condition on those obligations, not a fifth obligation. All four obligations must be met by the same witness progression. Products, demands, tool outputs, and operating consequences are evidence supplied to the house. Learning is established only when that evidence causes a retained computational change that affects later work beyond the unavoidable effect of carrying forward the changed product.