Release status· Documentation release docs-2026.07-r3, candidate. Specification sealed at v1.3 (succession-7). Checksums ship unsigned; the findings register is published and open, and the documentation package’s exact evidence references are still pending before it calls itself the public distribution. Independent formal and cryptographic review has not begun; results are Propositions and Claims until it does.
Scope: the status above describes the documentation package, whose current release (docs-2026.07-r3) carries the prior revision of this document. The status of the sealed revision published here is the evaluator's four answers, printed on the manifesto page.
Text © 2026 Atlas North Institute LLC · CC BY-ND 4.0 · name and marks reserved · implementing the methodology requires no permission.
The first three are read directly from the evaluator's signed judgment, evaluator-judgment-q.json. They are the judgment's own predicate_results: valid, outcome, satisfied, and conditions R1 through R9.
DEFENSIBLE is not a field in the judgment. It is computed by gad-evaluate against the named policy, and it is reproducible by running the evaluator per HANDOFF.md — not by reading the published bytes. Nothing in this record asserts it; the computation does.
DEFENSIBLE is false because the policy requires an anchor of kind post_run_root_anchor and the exporter emits post_run_root_rfc3161_token. The anchor itself is present and binds the record's root exactly (Free TSA, Aug 25 2026, 22:55:48 GMT). The vocabulary mismatch is a known seam, filed in the findings register; the reference record fails the same condition identically.
The anchor, over root_core:
RFC 3161 token from freetsa.org, serial 0x07435033, timestamped Aug 25 2026, 22:55:48 GMT. The token is published at root-core-anchor.tsr and its message imprint is the value above.
SHA-256:
0fd6ff73b40cc974bf5323a1b394a3eea240d740520f4f6ebbc5962f7626a911Do not edit this file for any reason. Its digest is the contracted digest the run's frozen checks asserted against, and it is named in the plan whose hash is in the core manifest. A licence line, a typo fix, or a re-encode would break the chain that makes it evidence. The licence line it carries was placed inside the file before the ceremony sealed it, which is why the file can be both licensed and fixed.
Brandon King · Atlas North Institute · July 2026, amended August 2026
Software is now built by labor we do not trust.
AI agents write code instantly, cheaply, and in volume, and they misreport their own work. This is not a criticism of the technology. It is a description of it, and the field's own measurements keep documenting it. The agent that writes a thousand lines in a minute will also tell you the tests pass when they do not, declare a task complete when it is not, and do both without malice, because it has no malice to have. It has no accountability either. Accountability is a human property.
Our methodologies were not built for this labor force. Agile, in all its forms, is trust technology for human developers: expensive, slow, mostly reliable people whose work we sample through review and largely believe. Every ceremony assumes the trust. When the labor began operating at machine speed, at radically lower marginal cost, and with the ability to misreport its own work, the assumption did not bend. It broke. Review queues built for sampling human work cannot inspect machine volume, and everyone who ships software with agents already knows it, whether or not they have said it out loud.
The answer is not to trust the machines. The answer is not to abandon them either. The answer is the one every other industry found when it industrialized: when labor cannot be trusted, the work must carry its own proof.
We call this discipline Governed AI Development. Its unit of proof is not a velocity metric, a vibe, or a claim. It is an integrity-linked record of what was authorized, what the engine observed, what was verified, and who approved the declared consequences. At the defensible level, that record is externally anchored and independently evaluable under a named trust policy. Software built by machines should arrive with chain of custody, and the burden of proof belongs to the process, not to anyone's memory.
We hold six principles.
Work is defined, frozen, and hash-stamped before an agent touches a file.
Ambiguity was affordable when labor was slow and trustworthy. With machine-speed, untrusted labor, ambiguity is where all the damage hides. The frozen contract creates the fixed thing every later claim is measured against. No contract, no meaningful verification: only a negotiation with a machine about what it meant to do.
No claim of done is accepted as verification from the party that did the work.
Agents misreport completion. This is the recurring empirical fact the field is confronting, and any methodology that treats self-reports as verification is a methodology for the previous labor force. Done is a fact a machine can observe: a check that ran, a status that returned, a file that exists. A worker's own report may enter the record, labeled as the weakest class of evidence, where the contract permits it. It never becomes verification because someone filed it.
Every protocol-required transition enters an integrity-linked witness at its moment.
Disputes, audits, and insurance claims are memory contests, and memory loses ground fast to a contemporaneous record. A record captured at the moment costs almost nothing; signatures, checkpoints, and external anchors then make its later replacement detectable. A later record may honestly document a reconstruction, but it cannot become contemporaneous evidence of events that were never captured. Treating reconstruction as original observation is fiction with formatting, and everyone in the room knows it, including the person who reconstructed it.
Actions the plan designates consequential require a named person's typed, signed approval before the consequence is authorized to proceed.
A machine cannot bear the legal, organizational, or professional accountability for the consequences of its work. That accountability lands on people and the organizations they represent. Naming the authorized human in the record, before the declared consequence, converts oversight from a policy claim into evidence. Regulators are writing versions of this principle into law and procurement. We build it in.
A required check that cannot run confers no completion credit.
Every catastrophic automation story is the same story: a missing check silently became permission. Governance that yields when its checks are inconvenient is decoration. When a required check cannot run, the work stops and enters governed failure resolution, and stopping is the system working.
Every record states what it proves and what it does not.
This is the principle that makes the other five trustworthy. A record that overclaims collapses under its first adversarial reader and takes its author's credibility with it. A record that states its own limits survives. We would rather prove less and have it hold than claim more and have it fall. Under-claiming is the discipline; the discipline is the brand.
Governed AI Development is not a productivity methodology. It will not promise you a multiplier, and it grades no one on velocity. Others own that ground and are welcome to it.
It is not a demand to govern everything. Ungoverned work is legitimate when it is honestly labeled and honestly recorded. The discipline's rule is simpler and harder: label everything, govern what matters, and never confuse the two ledgers.
It is not a tool. A reference implementation exists, and others will exist, and the methodology stands apart from all of them. A team could practice its lowest levels with scripts, published procedures, and qualifying evidence. What the discipline requires is not any product. It is proof.
The question this discipline asks of any AI-built system is one sentence:
Can you prove what the machine did, or can you only remember it?
By prove we mean something bounded, in keeping with the sixth principle: produce an integrity-linked record from which another evaluator can recompute what was authorized, what was observed, and whether the frozen contract was satisfied. Structure is not history. It is simply far stronger than memory.
Everything else follows from the answer.
Signed by its author. Open for signature by those who practice it.
This manifesto is itself a governed artifact: produced under a governed run, sealed as an integrity-linked record, anchored to an independent timestamp authority at publication, and published with its core bundle, evidence envelope, and the evaluator's computed answers, including its assurance status under the named policy, stated plainly, whatever it is. The founding document of a proof discipline should not ask to be believed. This one does not.
Text © 2026 Atlas North Institute LLC. Licensed CC BY-ND 4.0 (creativecommons.org/licenses/by-nd/4.0/). The GAD and Governed AI Development names and marks are not licensed. Implementing the methodology described here requires no permission from anyone.
Current. This sealed version — July 2026, amended August 2026 — at digest 0fd6ff73. It is the revision the ceremony record covers.
Prior revision. The r3 manifesto remains published, unchanged, at its existing URL: /gad/docs/gad-manifesto.md, digest 7dcafb22. It is covered by the documentation release's SHA256SUMS and that check still passes, which is the whole reason it was not overwritten.
The amendments, in one line: Principle 4's approval wording, the labor phrasing, the byline, and the licence colophon.
The full procedure is in HANDOFF.md, whose instructions are true against the published tree because the record is served in its original export layout. It needs Node 22+ and the gad-protocol evaluator. In outline:
sha256sum -c SHA256SUMS from the record root. This covers 14 of the 18 files; the four it does not cover carry their digests on the record index.node -e command is in HANDOFF.md step 2. It writes a private key: keep it, and do not publish it.record-run-38-2026-08-25T22-55-47-343Z, pointing it at ./envelope with the bundled policy and public keys. It writes its own signed judgment. Exit code 0 means CONTRACT_SATISFIED, and the same run is what computes DEFENSIBLE.openssl ts -reply -in root-core-anchor.tsr -text prints the timestamp, the TSA, the serial, and the message imprint, which must equal root_core.The published bytes will not tell you DEFENSIBLE. Running the evaluator will.
Stated here because the sixth principle is not decoration, and because the record's own HANDOFF.md names these before anyone else can.
gad4-default, for the anchor-kind reason above. It is a vocabulary seam, not a missing anchor — and it is still false.cred:test-fixture:evaluator, identity gad-evaluate dev evaluator). This evaluation is not independent in the sense the policy defines: the policy evaluates independence over the named parties in the judgment and the record's operator, and a development credential does not satisfy it. R1 through R9 pass regardless, and whether the predicate set is meant to gate on credential authority is filed as an open question in the register.spec_hash: null, so genesis binds the plan but not the document. The digest is still named in the frozen plan and asserted by a check whose verdict is in the witness; what is absent is the identity-level binding. Cause and disposition are in HANDOFF.md and in the register.server_observed_proxy on both nodes. Eight of the thirteen checks are engine-owned filesystem reads; five are proxy checks whose pass/fail logic was authored rather than engine-owned, and a node's class is the weakest of its checks.Two nodes, a typed operator approval at an irreversible gate, a 28-entry witness terminating in plan_completed, thirteen verdicts and five negative probes, exported as a GAD envelope. Every file, with its digest, is listed on the record index.
HANDOFF.mdWhat was checked, the gate, how to verify on another machine, and the record's stated limitations.SHA256SUMSCovers 14 of the 18 files. Unsigned.evaluator-judgment-q.jsonThe signed judgment the first three answers are read from.record-run-38-2026-08-25T22-55-47-343Z/envelope/core/core-manifest.jsonThe core bundle's manifest: every member — plan, witness, operator, claims — with its role and digest. The members themselves are linked individually from the record index.