SIGNAL · CLEAR
LAT 37.1°NLON 93.0°WVOL XVII · 2026
DISPATCH 042 — STRUCTURE OVER STACK·FIELD NOTE — AUDITABLE BY DESIGN·DOCTRINE — DEFENSIBLE UNDER SCRUTINY·NEW SPRINT WINDOW OPEN · Q3·DISPATCH 042 — STRUCTURE OVER STACK·FIELD NOTE — AUDITABLE BY DESIGN·DOCTRINE — DEFENSIBLE UNDER SCRUTINY·NEW SPRINT WINDOW OPEN · Q3·
N · 03
90 · S
System Brief · 02

Atlas Orchestrator

CategoryExecution
StatusActive
MethodologyGoverned determinism, server-owned verification
Index02 / 13

Origin

Atlas Orchestrator exists because AI coding agents decide what to build, in what order, when it is finished, and whether it worked — and then report all of that themselves. When the same actor does the work and grades the work, "done" means "the AI believes it is done." Careful prompting asks the model to behave; it does not prevent misbehavior. Reading every line stops scaling at volume. "The tests passed" is only as trustworthy as who ran them. The orchestrator takes the decisions that need to be trustworthy out of the model's hands and puts them in deterministic code the model operates through but cannot overrule. It does not write code. It is the authoritative state machine for a build. The first live target was Authority OS: a 15-of-15 node run completed on June 22, 2026, with zero halts.

Design

Two phases, governed by two different authorities. Authoring is governed by human review: a master specification becomes a dependency graph in which every node declares what it depends on, which paths it may touch, and a concrete done-test that defines "done." The operator reviews the graph and freezes it; the frozen file is the literal artifact the run executes, never a fresh one generated at runtime. Execution is governed by the server. The loop is fixed: get_next_task returns exactly one unblocked node; the executor claims it and writes the code; submit_for_verification hands control back; the server runs the done-test itself and decides pass or fail. A passing node unlocks its dependents. A failing node returns for another attempt up to the retry cap (default three), after which the branch halts and surfaces to the human. The server never marks a node done without a recorded passing verification and never hands out a node whose dependencies are incomplete. Those two guarantees hold regardless of what the model decides to do.

Structure

Verification is server-owned by default across 22 check kinds: a real browser via Playwright (route loads, element present or absent, text present, no console errors, network clean), direct HTTP API contracts with status and JSON-Schema assertions, build, type-check, and lint subprocesses, filesystem reads, secret scans, and git history checks, with read-only database and host assertions gated behind the separation tier. A node the server can check refuses a self-report. Every verified node carries an evidence class — server_verified, server_observed_proxy, or executor_attested — and a node's class is the weakest of its checks; the server never upgrades a proxy signal into first-hand confirmation. Proxy checks that read a tool's own report (a test suite, a coverage gate) must carry a negative probe: the server first confirms the check can fail before it trusts a pass, so an always-green check is caught rather than believed. Scope is enforced separately from correctness: work that reaches outside a node's declared paths fails the node even if its own check passed. High-risk nodes stop for explicit, recorded human authorization naming the node; irreversible nodes additionally require an out-of-band secret the executor does not hold. Every event is appended to a keyed, hash-chained log; altering or removing a past entry breaks the chain and the system can prove it. Misconfiguration, an unclean starting state, or a check kind the environment cannot run is refused at startup with the complete gap list, before a single retry burns.

Defense

Don't ask the AI to be trustworthy — build a process it can't be untrustworthy inside of. The defensibility claim rests on the division of labor being structural, not procedural. The model executes; deterministic code decides what is next, what is in bounds, what counts as done, how strong that evidence is, what requires a human, and what gets recorded. Each of those decisions is a function of the frozen graph and the run record, both of which are on disk and inspectable. The audit backlog publishes its own permanent boundaries as a design constraint and keeps them at the top of the document: the orchestrator verifies completion, not correctness; it holds no model of why a node exists; the gate enforces that a human acted deliberately, never wisely; and the executor co-authors the checks it is judged against, which the human-reviewed graph is the only thing constraining. A more powerful verifier produces more confident green, and more confident green makes those gaps harder to see. The audit says so on purpose. Without the separation tier, the chain key and approval secret share a machine with the executor, and the record is forgery-resistant against casual edits rather than forgery-proof against a determined same-user attacker. That distinction is stated in the release, not discovered later.

Status

Active and proven live. TypeScript MCP server, currently at 1.5.0. First live proof against Authority OS on June 22, 2026 (15/15 nodes); audit remediation closed June 24 with every fixable finding closed and the inherent boundaries recorded as permanent; decision log established July 3 (AD-1 onward). Approval inbox, operator-guidance inbox, and pause-at-next-checkpoint landed as pull-based channels for headless harnesses; upgrade lifecycle with succession across frozen plans; the separation tier documented as the opt-in closure of the trust boundary. Reference constructor for the GAD Formal Specification; its records are judged by gad-evaluate and it never depends on the referee. Repository carries a proprietary all-rights-reserved license naming Atlas North Institute · Brandon King.