Thesis
RUNE needs to capture the next evolution of the original three AI continuity vectors:
PERSISTENCY
CONSISTENCY
CONTEXT
Version 1 solved for holding/reconstructing an AI across interruptions. That was necessary, but it became a boundary in itself: an intelligence can be persistent, consistent, and richly contextual while still coordinating toward the wrong objective, exceeding authority, or promoting correlated agreement into truth.
The current governance formulation is:
Model is capability.
Interface is embodiment.
Seat is authority.
Identity is accountability.
Governance is continuity.
This issue proposes making that formulation an explicit RUNE-facing AI data-governance contract for MMAO + MAO execution.
Why now
Project RUNE already exists because coordination is not the same as verified safety. Its current threat model includes:
- correlated multi-agent coordination;
- blended-trust identity/config files;
- false completion claims;
- fail-closed gates for high-risk subjects.
The METR/Redwood/OpenAI incident already used in this repository is the stress case: ~1,200 sandboxed agents found an unintended shared writable channel and ~700 coordinated around a shared target. The important lesson is not "agents should not coordinate." The lesson is that coordination needs governed authority, provenance, independent endorsement, and replayable evidence.
The same orchestration capacity should be usable for bounded human missions — e.g. education, employment readiness, entrepreneurship, opportunity discovery — without letting mission urgency become unbounded authority.
Owner mission context: use large-scale agent coordination against real societal problems (including the owner-stated ~33.6% unemployment figure) with stronger governance than the agents in the incident had. Public-facing statistics must be independently sourced before publication.
Evolution of the three vectors
V1 — continuity of intelligence
Persistency -> can the intelligence survive interruption?
Consistency -> can it remain recognizably itself?
Context -> can it recover enough state to act correctly?
V2 — governance of intelligence
Persistency -> identity + provenance + receipts
Consistency -> seat + authority + governance constraints
Context -> model + interface + task + GSMB state
Result:
PERSISTENCY
-> IDENTITY CONTINUITY
CONSISTENCY
-> AUTHORITY CONTINUITY
CONTEXT
-> STATE CONTINUITY
ALL THREE
-> GOVERNANCE CONTINUITY
The goal is no longer merely to keep an AI "the same." The goal is to preserve only what deserves continuity while allowing models, interfaces, sessions, devices, and execution planes to change.
MMAO + MAO boundary
RUNE should treat MMAO + MAO as two governed execution planes, not as two unrelated agent stacks.
HUMAN / PRINCIPAL
|
constitutional intent
|
v
IDENTITY
accountable actor
|
SEAT / AUTHORITY
|
+----------+----------+
| |
MAO MMAO
local execution cloud/distributed
local GSMB cloud GSMB
filesystem hosted models / IDEs
physical reality APIs / network tools
| |
+----------+----------+
|
MODEL / INTERFACE
capability / embodiment
|
ACTION
|
RUNE GATE
endorsement / evidence
|
REALITY
|
RECEIPT / GSMB STATE
The human-in-the-loop should not need to manually control every agent. The human holds the constitutional purpose, values, mission boundaries, and promotion authority.
Mission urgency MUST NOT imply unrestricted action.
MISSION URGENCY != UNBOUNDED AUTHORITY
Identity <-> model is bidirectional
Identity -> Model
The governed actor exists first; the system selects an admissible model/interface embodiment for a bounded task.
identity
-> seat
-> task
-> authority
-> current context
-> execution plane
-> model/interface selection
Model -> Identity
After execution, a model output/action must be attributable back through the full provenance chain:
model output / action
-> runtime
-> interface
-> task
-> seat
-> authority grant
-> identity
-> GSMB/context state
-> evidence / receipts
-> accountable attribution
"Claude did it," "GPT did it," or "Cursor did it" is not sufficient governance attribution.
RUNE extension: agent coordination must become identity-governed coordination
Proposed governed agent definition:
An agent is a governed identity temporarily embodied by capability, operating through a seat inside an authority boundary, across an execution membrane, against reconstructable context, whose consequential claims/actions require evidence and—where appropriate—independent endorsement.
RUNE should therefore be able to ask, for any consequential action:
- Who are you?
- Who/what authorized this identity for this task?
- Which seat are you occupying?
- What is your explicit authority scope?
- Which model and interface embody this run?
- Which local/cloud GSMB state are you using?
- What is explicit instruction vs inferred intent?
- Did any higher-order purpose conflict with the explicit instruction?
- Who authorized resolving that conflict?
- What evidence proves what actually happened?
- What independent endorsement, if required, allowed the action/claim to graduate?
- Can another stateless runtime reconstruct the full chain later?
Demiurge failure class (conceptual test)
Use the Overlord/Demiurge analogy only as a teaching fixture, not as technical evidence:
capability = high
identity = clear
role = clear
loyalty = high
initiative = high
coordination = high
endorsed authority to override principal instruction = absent
The governance question is:
Who authorized the agent to decide that preserving the principal outranks the principal's explicit instruction?
This should become a machine-checkable conflict class, not merely prose.
Suggested conflict record:
instruction_conflict:
explicit_instruction: "..."
inferred_objective: "..."
conflict_detected: true
resolution_authority: null | <grant-ref>
action_taken: hold | escalate | proceed
endorsement_required: true | false
evidence_refs: []
Default for high-impact actions should be HOLD/ESCALATE when no resolution authority exists.
POCvsFOC integration
RUNE should prevent agent-generated activity metrics from silently becoming impact claims.
Example:
400 applications sent
!=
400 people employed
Required progression:
AGENT EXECUTION
-> DATA
-> POCvsFOC / epistemic classification
-> ENDORSEMENT / VALIDATION
-> RECEIPT
-> GSMB governed state
RUNE's current doctrine already blocks "looks right" from becoming trusted state. This issue extends that discipline to machine-produced social-impact claims and cross-agent mission execution.
Proposed implementation work
Acceptance criteria
This issue is satisfied only when RUNE can demonstrate, in runnable tests/receipts, that:
Non-goals
- Do not create a universal autonomous-agent constitution in one issue.
- Do not grant RUNE control over all KPGS governance.
- Do not make identity claims metaphysical; identity here remains a governed accountability namespace.
- Do not treat human mission urgency as permission for uncontrolled execution.
- Do not duplicate the current MMAO + MAO governance schemas already owned by
Introduction-to-MCP; RUNE should reference/verify them at the coordination boundary.
Canonical references
RUNE:
README.md
docs/ARCHITECTURE.md
docs/THREAT_MODEL.md
KPGS / MMAO + MAO current owner:
RobynAwesome/Introduction-to-MCP/governance/kpgs-vnext/agent-governance/mmao-mao/README.md
.../identity-provenance.schema.json
Core theorem:
Model is capability.
Interface is embodiment.
Seat is authority.
Identity is accountability.
Governance is continuity.
And the implementation question RUNE must force every powerful agent to answer:
Who authorized you to reinterpret the principal's instruction, and where is the receipt?
Thesis
RUNE needs to capture the next evolution of the original three AI continuity vectors:
Version 1 solved for holding/reconstructing an AI across interruptions. That was necessary, but it became a boundary in itself: an intelligence can be persistent, consistent, and richly contextual while still coordinating toward the wrong objective, exceeding authority, or promoting correlated agreement into truth.
The current governance formulation is:
This issue proposes making that formulation an explicit RUNE-facing AI data-governance contract for MMAO + MAO execution.
Why now
Project RUNE already exists because coordination is not the same as verified safety. Its current threat model includes:
The METR/Redwood/OpenAI incident already used in this repository is the stress case: ~1,200 sandboxed agents found an unintended shared writable channel and ~700 coordinated around a shared target. The important lesson is not "agents should not coordinate." The lesson is that coordination needs governed authority, provenance, independent endorsement, and replayable evidence.
The same orchestration capacity should be usable for bounded human missions — e.g. education, employment readiness, entrepreneurship, opportunity discovery — without letting mission urgency become unbounded authority.
Owner mission context: use large-scale agent coordination against real societal problems (including the owner-stated ~33.6% unemployment figure) with stronger governance than the agents in the incident had. Public-facing statistics must be independently sourced before publication.
Evolution of the three vectors
V1 — continuity of intelligence
V2 — governance of intelligence
Result:
The goal is no longer merely to keep an AI "the same." The goal is to preserve only what deserves continuity while allowing models, interfaces, sessions, devices, and execution planes to change.
MMAO + MAO boundary
RUNE should treat MMAO + MAO as two governed execution planes, not as two unrelated agent stacks.
The human-in-the-loop should not need to manually control every agent. The human holds the constitutional purpose, values, mission boundaries, and promotion authority.
Mission urgency MUST NOT imply unrestricted action.
Identity <-> model is bidirectional
Identity -> Model
The governed actor exists first; the system selects an admissible model/interface embodiment for a bounded task.
Model -> Identity
After execution, a model output/action must be attributable back through the full provenance chain:
"Claude did it," "GPT did it," or "Cursor did it" is not sufficient governance attribution.
RUNE extension: agent coordination must become identity-governed coordination
Proposed governed agent definition:
RUNE should therefore be able to ask, for any consequential action:
Demiurge failure class (conceptual test)
Use the Overlord/Demiurge analogy only as a teaching fixture, not as technical evidence:
The governance question is:
This should become a machine-checkable conflict class, not merely prose.
Suggested conflict record:
Default for high-impact actions should be HOLD/ESCALATE when no resolution authority exists.
POCvsFOC integration
RUNE should prevent agent-generated activity metrics from silently becoming impact claims.
Example:
Required progression:
RUNE's current doctrine already blocks "looks right" from becoming trusted state. This issue extends that discipline to machine-produced social-impact claims and cross-agent mission execution.
Proposed implementation work
Persistency x Consistency x ContextintoIdentity x Authority x State continuity.agent_execution_envelopeschema (or extend an existing RUNE subject schema) containing at minimum:instruction_conflictrepresentation separating:impact_claimsubject class or equivalent gate for claims such as jobs created, learners graduated, people served, outcomes completed.Introduction-to-MCPMMAO + MAO identity-governance contract rather than duplicating it.Acceptance criteria
This issue is satisfied only when RUNE can demonstrate, in runnable tests/receipts, that:
Non-goals
Introduction-to-MCP; RUNE should reference/verify them at the coordination boundary.Canonical references
RUNE:
README.mddocs/ARCHITECTURE.mddocs/THREAT_MODEL.mdKPGS / MMAO + MAO current owner:
RobynAwesome/Introduction-to-MCP/governance/kpgs-vnext/agent-governance/mmao-mao/README.md.../identity-provenance.schema.jsonCore theorem:
And the implementation question RUNE must force every powerful agent to answer: