SIGNAL · CLEAR
LAT 37.1°NLON 93.0°WVOL XVII · 2026
DISPATCH 042 — STRUCTURE OVER STACK·FIELD NOTE — AUDITABLE BY DESIGN·DOCTRINE — DEFENSIBLE UNDER SCRUTINY·NEW SPRINT WINDOW OPEN · Q3·DISPATCH 042 — STRUCTURE OVER STACK·FIELD NOTE — AUDITABLE BY DESIGN·DOCTRINE — DEFENSIBLE UNDER SCRUTINY·NEW SPRINT WINDOW OPEN · Q3·
N · 03
90 · S
System Brief · 01

GAD (Governed AI Development)

CategoryGovernance
StatusSealed Specification (v1.3, succession-7)
MethodologyGoverned determinism; decidable predicates over a finite witness
Index01 / 13

Origin

Software is now built by labor we do not trust. AI agents write code instantly, cheaply, and in volume, and they misreport their own work — not from malice, but because accountability is a human property and the agent has none. Agile in all its forms is trust technology for human developers: expensive, slow, mostly reliable people whose work we sample through review and largely believe. When the labor began operating at machine speed, at radically lower marginal cost, and with the ability to misreport its own work, the assumption did not bend; it broke. GAD is the answer every other industry found when it industrialized: when labor cannot be trusted, the work must carry its own proof. GAD is the methodology name; governed determinism is the design philosophy underneath it. The methodology formalizes the discipline first practiced in running code by Atlas Orchestrator and Waypoint, its parent works and reference implementation. Its unit of proof is not a velocity metric, a vibe, or a claim. It is an integrity-linked record of what was authorized, what the engine observed, what was verified, and who approved the declared consequences.

Design

Six principles govern the practice. Contracts before execution: work is defined, frozen, and hash-stamped before an agent touches a file. Verification over attestation: no claim of done is accepted as verification from the party that did the work. Evidence over recollection: every protocol-required transition enters an integrity-linked witness at its moment. Humans at declared consequence: actions the plan designates consequential require a named person's typed, signed approval before the consequence is authorized to proceed. Fail closed: a required check that cannot run confers no completion credit. Honest boundaries: every record states what it proves and what it does not. The formal specification extracts the algorithms underneath the prose so that the status of AI-executed work stops being a judgment and becomes a computation. Its core reduction, load-bearing everywhere: governed execution is a decidable predicate over a finite, integrity-linked witness; contract satisfaction is a separate predicate over the same witness. Two algorithms carry the whole discipline — CONSTRUCT, the run loop a conforming implementation executes, and EVALUATE, the computations anyone can run on any machine. Four statuses ascend in strength: VALID_RECORD, OUTCOME, CONTRACT_SATISFIED, and DEFENSIBLE. The separation preserves the doctrine's central idea: a halt can be the system working.

Structure

Six invariants hold the specification together. I1, contract precedence: the plan is bound by hash and the witness by sequence. I2, producer never grades: the executor has no write path to the record, no keys, and engine-computed surfaces it cannot collapse. I3, witness at the moment: contiguous sequence, non-circular chain, checkpoint coverage, sealed lifecycle, and the executor-outcome rule by which even a vanished worker leaves evidence. I4, named human at consequence: registered principals and credential signatures, with gated completion meaning APPROVED. I5, unknown is fail: totalization, allowlist fences, breakers, executor failure as first-class FAILED, fail-closed export. I6, claims carry boundaries: typed claims over evidence with mandatory noncoverage, so machine judgments are unrepresentable. Five levels, cumulative above the Ungoverned floor. GAD-0, Ungoverned: agents run; nothing is recorded. GAD-1, Recorded: the minimum record exists for every executor invocation. GAD-2, Verified: engine-side evaluation, and no completion credit from attestation alone. GAD-3, Governed: the exported record satisfies conditions R1 through R9. GAD-4, Defensible: under a named trust policy, an external anchor and a valid attestation from an evaluator independent of the operator. Level four is a property a bundle has demonstrated, and the attestation is the receipt. Conformance runs in three levels — bundle, constructor, operational — and no passing record confers conformance on the tooling that produced it. The specification's prose is frozen by its own stewardship rule. Change arrives exclusively from concrete findings recorded in a companion register, and a register ruling is not an amendment: a frozen specification changes only by numbered, operator-signed succession, with the delta as a sidecar beside the spec.

Defense

We would rather prove less and have it hold than claim more and have it fall. The sixth principle is what makes the other five trustworthy, and the specification applies it to itself. Its normative header labels Section 1's results Propositions and Claims, not Theorems, until independent formal and cryptographic review completes, and states that record-level Trial 0 results do not establish general implementation conformance or GAD-4 defensibility. The sealed v1.3 file cannot be edited: its SHA-256 digest is bound into the succession-7 record, and any changed conformance conclusion is disclosed by signed succession or correction notice rather than by rewriting a historical result. The documentation releases practice the same discipline on themselves. Each release carries a manifest naming every governed artifact with its role, status, and digest; predecessors are preserved exactly and never overwritten; the public-candidate README states plainly that it is not yet the public distribution and names the blocking items. Licensing, governance, and trademark documents are recorded as deliberately absent pending counsel rather than improvised. GAD is not a productivity methodology and promises no multiplier. It is not a demand to govern everything: label everything, govern what matters, never confuse the two ledgers. It is not a tool; the reference implementation exists and the methodology stands apart from it.

Status

Sealed. Specification v0.1 July 12, 2026; sealed at v1.3 by succession-7 on July 17, with all seven Ed25519-signed succession records and the companion register held in gad-protocol (64 findings, 6 rulings at seal; register open thereafter). Components: Formal Specification v1.3, Manifesto, Executive Guide, Glossary, Standardization Track, and the Methodology and Certification Strategy (internal rev 3). Documentation releases r1 through r3, July 19–20, split into internal and public-candidate packages, prepared and not yet publicly released. Evidence release gad-evidence-2026.07 (r1 through r4) and six field-record presentation pages with three preserved revisions, drawn from the Waypoint and Atlas Orchestrator build corpus. A six-article campaign frozen and unpublished. Independent review (Phase 5) not begun. gad-protocol is the referee arm; Atlas Orchestrator and Waypoint are the reference implementation; the PAM audit methodology is positioned as the assessment instrument for the maturity ladder.