Record class: Previous-protocol construction record. Presentation revision 3: terminology and claim-boundary corrections applied per review; revisions 1 and 2 preserved byte-exact in this archive; underlying record bytes unchanged. Record class detail: previous-protocol constructor-migration record. The evaluator acceptance shown at node thirteen applied to the test envelope produced during that node; it did not confer v1.3 conformance on this record's own keyed witness. Historical evidence label: server_observed_proxy; current interpretation: engine capture over a worker-authored proxy signal, effective class proxy with a bound, valid probe.
Read this as
Atlas North Institute · field record No. 4 · July 14, 2026

The run that told the truth.

Fifteen nodes rebuilt an orchestration engine to conform to a published standard, and at the end a separately executable evaluator, run from a read-only checkout, read the test envelope the engine produced and accepted it. Along the way the run crashed repeatedly, caught a regression it had caused in its own earlier work, and twice produced a plausible recommendation to edit the frozen plan. The plan was not edited. This is the record of what that cost and what it proved.

What happened

Over roughly fifteen hours and many sessions, a frozen fifteen-node plan rebuilt Atlas Orchestrator to speak the protocol defined in the GAD Formal Specification: a public signed witness, two-axis evidence classing, session accounting that treats a dead executor as recorded fact rather than silence, and a fail-closed export. The decisive moment came at node thirteen, where the separately executable evaluator built in the previous phase, from a read-only checkout, with no knowledge of this run, read the envelope Atlas produced and returned valid, correct outcome, every condition satisfied. The constructor now speaks the referee's language.

15 / 15
nodes verified done
83
chained entries, seq 0 through 82
14.8 hours
across many sessions, one chain
1
reopen, authorized by name, on the record
1
node failed, retried, and passed within budget
0
frozen plans edited · 0 waivers · 0 chains broken
In plain terms: this run's history is hash-chained end to end and verified at export: tamper evidence within the engagement trust model, with no independent time anchor claimed. Every completion claim was checked by machinery outside the worker's session, and every checker first demonstrated a failure under its planted-defect probe. This record does not prove the code is semantically correct against the specification, does not prove the efficiency commentary below, and cannot be verified by the evaluator this work produced: this witness is still the previous protocol's keyed chain. Two known defects are named here rather than hidden, one of them still open. The run's engine state ended non-terminal on that open defect even though all fifteen nodes verified. A record that claimed more would be worth less.

The part worth reading

Near the end, the run's own regression sweep caught something real: an earlier node's test had been silently broken by a later node's stricter rule. Node ten had implemented a ruling that forbids reviving a node whose safety breaker has tripped. Node four's test still expected the old, looser behavior. Nothing external caught this. The machinery caught itself, recorded it on the chain, and refused to call the build complete while it stood. see the self-caught regression →

The fix was small and correct. Blessing it was not. Twice, an engine defect, since named and recorded, attributed one run's committed work to another run's node and blocked a correct node from verifying. Twice, a capable executor recommended the same remedy: edit the frozen plan and reload. It was not a foolish suggestion; it was the only path the broken engine left visible. It was declined both times. A frozen contract is never edited to make a check pass. The ceremony was abandoned instead, the fix was closed on three distinct verification runs, and the defect was written down as the highest-priority item in the next phase. see the halt that ended the ceremony →

Why this record is worth more than a clean one

A flawless run proves nothing: flawless is what fabrication looks like. This one crashed, stalled, orphaned a claim, failed a node, caught its own regression, and hit an engine bug three times in three different costumes. Every one of those events is on the chain with a timestamp. The reopen carries the operator's name and his exact words. The failed node shows its retry and its recovery. The abandoned ceremony is written into the register with the reasons. Nothing was waived. Nothing was backfilled. No frozen plan was edited, at the end of a fifteen-hour day, when editing it was the recommended option. That is the only test of governance that means anything: not whether it holds when it is convenient, but whether it holds at hour fifteen with a plausible shortcut on the screen.

On efficiency, labeled as commentary

Analysis, not chained evidence: the record proves the run's duration and interaction pattern; it cannot prove a counterfactual that never executed. The frozen plan carried the entire specification, so the executor was never told what to build twice. The same brownfield scope executed ungoverned, estimated from this operator's own prior rhythm, runs into the hundreds of authored prompts across many days, most of them respecification and correction. The friction in this run was almost entirely in the cockpit's session lifecycle, not in the work: the plan itself never had to be explained again.

Identity: what ran, exactly

Frozen plan (authored identity)698503336c0db6326e535b6e7b66a2d0340d7478baf7222f331cc607801fb72e
Master spec hash6d685e1338dfe7786c5ece0c5fbb1caf8fda95ca914c2986b08d4f8073a05945
Genesis hash (chain root)2140e574d35066b80e16d2bcdcf1e6397547805955d8180f3cad54d87421a7bb
Repository at run startfc885caa7e3467803d7c1396fb3974d0f022b7d5
Engine · cockpitAtlas Orchestrator 1.5.0 · Waypoint 1.1.0
Nodes · retry cap · mode15 · 3 · supervised, scope enforced, clean-tree required
Corrective plan (superseding)50b618e887e5cb64050107c8794f09d08011213e83b0e7b3d0605a08d71028f3

The fifteen nodes, timed from the chain

Durations are claim-to-verification, computed from the entries below. Every check was run by the engine against executor-authored tooling, so every node carries the honest class for that arrangement, server_observed_proxy, and every checker holds a negative probe: a committed planted defect it must detect, or its passes do not count.

#nodetitledurationchecksretries
01p2-01-mode-canon-signingFoundations: protocol_mode, canonicalization, Ed25519 signing10m 36s10
02p2-02-witness-chainTyped witness writer: public chain, issuer table, dual-write11m 01s10
03p2-03-checkpoints-sealingCheckpoints, coverage, sealing, snapshot seal10m 24s10
04p2-04-freeze-terminalsTyped freeze and terminals wired to the store57m 16s10
05p2-05-session-apiThe GAD-1 session API: dispatch, executor_exit, execution_result16m 08s10
06p2-06-scope-transitionsTyped scope: mechanical flags, removal recheck, signed closure26m 28s10
07p2-07-gates-successionTyped gates per RUL-4 and the succession API30m 07s10
08p2-08-verdictsSigned two-axis verdicts for every evaluation attempt33m 58s10
09p2-09-probes-effclassTyped probes, effective class, the GAD-2 floor38m 23s10
10p2-10-r8-rulingsRUL-2 and RUL-3: breaker and waiver enforcement13m 28s10
11p2-11-claims-exportTyped claims and the fail-closed B_core export18m 45s10
12p2-12-harnessThe fixture harness: one full v0.6 run, every path exercised15m 07s10
13p2-13-referee-gateEXIT GATE: the referee accepts Atlas's envelope, cold482m 48s10
14p2-14-acceptance-quartetAcceptance tests 8, 9, 13, 14 on the record9m 10s10
15p2-15-legacy-greenNo regression: the whole legacy suite, lint, and build16m 16s11 retry

Two defects, named

REG-11, closed. An earlier node's test asserted behavior that a later node's ruling forbade. Caught by this run's own regression sweep at chain entry 82, fixed test-only, and closed on three distinct verification runs: a cold rebuild on a different machine and operating system, an operator terminal run, and the corrective node's own green check. Closed by commit, not by ceremony, for the reason below.
REG-12, open, and the highest-priority engine defect in the migration. The scope check compares the working tree against a stale recorded commit rather than the tree as of run start, so one run's committed work is attributed to another run's node. It defeated a correct node three times in three forms: it blocked the main run's regression re-verify, it prevented the corrective plan from resuming across a supersede boundary, and it halted the corrective run on a file that node never touched. Its real cost is not the friction. Twice it manufactured pressure to edit a frozen plan, because it left an honest executor no other visible remedy. The fix is specified in the register and belongs to the next phase.

The boundary this record refuses to blur

The constructor cannot ratify its own conformance. This run's witness is still the previous protocol's keyed, HMAC-linked chain: verified end to end at export, tamper-evident within the engagement trust model, carrying no independent time anchor. The evaluator that accepted Atlas's envelope at node thirteen cannot verify the record of the run that produced it. One evidence path, separate verification of a human-approved high-risk step, was honestly deferred to the next phase because the approver identity is not yet written into the frozen plan in the referee's format; the run's exit gate proves the four paths that pass today and says so. And the run's engine state ended non-terminal on REG-12 even though every node verified. Work complete, run-state non-terminal, reason recorded. Conformance Trial 0 judges these books, not this record.

What this record proves, and what it does not

It proves the plan was frozen and hash-addressed before work began; that every completion claim was checked outside the worker's session with its evidence class stated; that every checker demonstrated the capacity to fail before its passes counted; that the four bypass attempts from the audit checklist were each refused on the record; that a separately executable evaluator accepted the constructor's test envelope cold, a result that did not confer v1.3 conformance on this field record's own keyed witness; and that a node which failed was retried within budget and recovered rather than waived. It does not prove semantic correctness against the specification, the efficiency commentary, or this record's own conformance to the standard its contents implement. Those verdicts belong to the adversarial vectors, the second evaluator, and Trial 0.

The complete chain, entry by entry

All 83 entries of the main run, seq 0 through 82, exactly as written at the moment. Click any entry for its raw form and its link to the next.

The corrective run: 7 entries, ending in a halt

The one-node plan authored to bless the REG-11 fix through a governed node. Its test passed. It halted anyway, on REG-12, naming a file it never touched. The ceremony was abandoned rather than the contract bent.

Verification panel (presentation rev 3)
Presentation: field-record-4-truth.html · rev 3
Underlying run project: project-3-1783997559397 (digest-matched in the supplied runs corpus)
Matched digest: fc885caa7e3467803d7c1396fb3974d0f022b7d5 (commit identity) located in the project logs
Protocol: constructor migration toward v1.x; witness remains previous-protocol
Anchor: none claimed