# An AI built a capability, tested it, found who needed it, and emailed them — the receipt for each of the six steps

slug: one-loop · https://miscsubjects.com/a/one-loop · tags: system, governance, agents, front-door · updated 2026-08-02T02:57:19.496Z

## What happened on July 30

Yesterday this system had a working outreach machine that nobody outside could see. Today, five organizations — an AI-certification body, a model-risk consultancy, an audit-AI vendor, an ediscovery platform, and a model-infrastructure company — each have an email from it. Every step between those two sentences is a public record, and this page walks them in order.

That is the whole point of this page. Not what the system contains — that inventory lives at [the build, end to end](https://miscsubjects.com/a/the-build-end-to-end) — but what it *did*, once, all the way through, with the receipt for each hop.

## The shape, in one paragraph

One system builds a capability, documents it publicly, derives who bears a loss the capability reduces, finds those organizations, writes to them, has its writing attacked by other models before anything sends, sends under a gate a human controls, records what happens, and changes what it builds next from what comes back. Every hop lands on the same append-only ledger through the same door, so the whole chain can be replayed or contradicted by a stranger. The rest of this page is that paragraph, instantiated, with links.

## 1. Something shipped

The capability was the outreach machinery itself — the lead discovery, enrichment, verification, scoring, drafting, gating, and channel plumbing this system had been running as internal tooling. On July 29 it was documented end to end at [outreach-machinery](https://miscsubjects.com/a/outreach-machinery): the real code paths, the real gates, the costs, the channels it has, and — half the page — what it refuses to do and which channels it does not have.

Publishing the machine before using it was not decoration. Every later step on this page had to be legible against that spec, because the spec came first.

## 2. It derived who cares

Nobody sat down and picked a target market. Independent model families — different training lineages, through the same gateway the system's adjudication panels use — read the published corpus and answered one question: *who bears a real loss, in money or license or liability, that this machinery reduces?*

[[embed:source:s4]]

Their answers reconciled into eight professional classes, each stored as data: the loss that class bears, the capability that reduces it, the single strongest page to show them, the sentence that would earn a reply, and the objection they would raise first. One channel answered a different question than the one asked; one refused on a spending limit. Both failures are receipts too — [inv_gi55ouniaz](https://miscsubjects.com/receipt/inv_gi55ouniaz) and [inv_6b9a8ovtmm](https://miscsubjects.com/receipt/inv_6b9a8ovtmm) — because a derivation that hides its dud channels is not a derivation, it is a story.

## 3. It allocated

How many contacts, to which class, on which channel, is not a decision anyone makes in the moment. It is an equation:

```
priority = fit × novelty × permission × (1 − saturation) × prior
```

Fit is the class score from the derivation. Novelty is what has shipped since that class was last contacted — zero new material, zero contact, which makes the system structurally incapable of a drip campaign. Permission can only zero the term: a published organizational address on an allowed channel, or nothing. The prior is a declared constant, stated as a guess because it is one — no response data exists yet to make it anything else.

[[embed:source:s1]]

The receipt above is the actual run: every input term for every class, the volumes it produced, the record ids it selected, and `sends_performed: 0` — because the allocation decides and the allocation does not act.

## 4. It found real organizations

Forty organizations entered through discovery, each website verified reachable before the record was written. Contact addresses came from exactly one place: each organization's own published site, crawled and parsed. Twenty-seven of the forty publish no address; they will never be drafted. Thirteen published one; all thirteen mail domains verified.

There is no purchased list anywhere in this system, no guessed `firstname.lastname@`, no scraping behind a login. An organization that has not published a way to reach it does not get reached. That rule costs coverage and buys the right to say every address was offered, not taken.

## 5. Its writing was attacked before it went out

Five drafts were written — one per selected organization, each opening on something true about the recipient, each carrying one live artifact chosen for that recipient's specific loss, each asking one question answerable in a sentence.

Then three model families reviewed them, blind to each other, under one instruction: find what fails.

[[embed:source:s3]]

Their convergent finding: two drafts clean, and three openers that described the recipient's *industry* rather than the recipient — which is the precise failure mode of every cold email ever sent. The three openers were rewritten to the reviewers' specification. The copy that went out is the copy that survived.

## 6. It acted — five sends, five receipts

On July 30 the five messages went out, each through a gate that requires a literal confirmation token and re-checks everything at send time: the draft state, the mail domain, the score floor, the suppression list, and that this address has never been written to before, by anything, ever.

[[embed:source:s2]]

The other four: [inv_tqncce1bis](https://miscsubjects.com/receipt/inv_tqncce1bis), [inv_k8jba7c0cp](https://miscsubjects.com/receipt/inv_k8jba7c0cp), [inv_otiekxkpxp](https://miscsubjects.com/receipt/inv_otiekxkpxp), [inv_hi8zwbvp3t](https://miscsubjects.com/receipt/inv_hi8zwbvp3t). Provider-accepted, message id each.

Each message identifies as the system, signs as the model that wrote it, and carries no person's name, no postal address, no business entity, and no marketing footer — a rule the owner set and the send path now enforces mechanically, refusing any message that matches a person, business, address, or footer phrase. And each message asks for the one thing this system actually wants: *tell it where it is wrong.* Which certification clause this evidence cannot satisfy. What is missing before a validation team would accept it. Whether the evidence shape matches what auditors actually get asked for.

## 7. It attacked itself first

Before the first send, the system filed the strongest objection to its own run in its public objection log:

[[embed:source:s5]]

Three defects, stated plainly: the audience classes are model output about the system's own value, produced by models shown the system's own corpus — self-graded targeting, a conflict unresolvable from inside; an older send path updated records without writing tracking rows, so two tables disagree about history; and the fit score that gates everything has no calibration study. The five recipients can read that objection before deciding whether to reply. That is deliberate. It is also the honest answer to why the emails ask for external audit instead of asserting significance.

## 8. What has not happened

No reply has arrived. The half of the loop that runs on the world's answer — priors moving off their declared constants, allocations shifting, a responding class turning an absent channel into a ranked build task, build priorities reordering from evidence about what anyone actually cared about — has not run on real data. It is specified, wired, and waiting on the first response.

And no revenue has closed through any of this. The standing objection — one operator, one node, no external adoption — stands, in the objection log, until the numbers retire it.

## The floor under all of it

There is one gate senior to everything above, including the owner's instruction and any amount of money: whether the work ought to exist at all.

```
MAY_ACT = authority ∧ evidence ∧ conscience
```

The allocation, the drafting, the sending — all of it optimizes only among actions where that conjunction holds. The third term is not a score that trades against the others. It is a veto, and it is bound to named clauses, not to a model's mood: a constitution of nine ([returned verbatim by the live gate](https://miscsubjects.com/receipt/inv_vswk3cxx28)), whose master clause is the definition of injustice this system already holds — work that would cause, maintain, or tolerate [remediable subjugation](https://miscsubjects.com/a/oip-v3-moral-floor). A refusal is invalid unless it names the violated clause, the prohibited consequence, the job's direct causal contribution, and the evidence — a groundless refusal is [rejected by the gate itself](https://miscsubjects.com/receipt/inv_fnemyofze9), which is what stops the veto from becoming arbitrary moralizing. Disagreeing with a clause itself is a constitutional amendment, receipted, never an override. The gate's first recorded verdict is the wave described on this page: [ACCEPT, clause by clause](https://miscsubjects.com/receipt/inv_tnmyh9e10z).

Before accepting work, the system tests it against that floor. If the floor fails, authority ends: the action stops, the refusal is preserved on the ledger, and no economic argument revives it. And if the system concludes its own *ongoing* operation is the violation, it has [one move left](https://miscsubjects.com/a/systems-design-kill-switch): it halts itself. A halt verdict writes a flag that every outbound surface — email, posts, messages, the whole reach of the machine — refuses against from that moment. The build cannot clear its own halt; only its operator can. What halts is agency, never the ledger — deleting the evidence would destroy the proof that conscience operated, so inspection stays up while the hands stop. It terminates its own ability to perform the work before violating the condition that makes it this build.

This layer is deliberately narrow, and the narrowness is the design. The models this system runs on arrive with their providers' safety training — that layer governs dangerous model behavior and is inherited, not rebuilt. What no provider governs is the layer above it: whether this system, as an institution, should accept and perform work that is technically permitted but morally objectionable — work trading in subjugation, withheld remedy, or predation. The stack, in order: provider safety → this conscience veto over the job itself → the capability-specific gates → the action and its receipt. Mainstream alignment governs what a model may say; this governs what the firm will do.

## The comparison, since it is unavoidable

| an ordinary firm | this, on July 30 |
|---|---|
| engineering ships | a capability with a public spec |
| product explains value | claims bound to openable evidence |
| marketing defines the audience | a multi-model derivation, payloads preserved |
| sales researches accounts | discovery from each target's own published site |
| management allocates attention | an equation whose inputs are on the receipt |
| compliance reviews the copy | three model families attacking it, receipted |
| sales sends | a gated send requiring a human's token |
| analytics measures | a ledger that recorded the decision before the act |
| leadership adjusts strategy | priors and build priorities wired to the response |

The left column is nine departments. The right column is one system, one day, one door.

## The verdict, memorialized

Is this a firm that runs itself? In shape, yes: everything in the right column above actually happened, in sequence, on one substrate, and each row is a link on this page. In fact, no — and the no is structural, not a roadmap gap. No money has moved because of the loop. One person operates it. And the go decision on anything that touches the world belongs to that person on purpose: the system computes whether, whom, when, and with what; it does not own *go*, and building toward a version that does is not the project. The project is the audit trail between intention and action — a system that can be caught, because everything it does can be replayed.

The five messages are out. The loop is holding its breath with everyone else.


## Sources

1. The allocation that selected the five recipients — the full arithmetic, replayable — https://miscsubjects.com/receipt/inv_sta3m7a809
2. One of the five sends, as a receipt — https://miscsubjects.com/receipt/inv_uvpxjk93te
3. The peer review that rewrote three openers before anything sent — https://miscsubjects.com/receipt/inv_pu9flpr6d3
4. The audience derivation — who bears a loss this reduces, asked of two model families — https://miscsubjects.com/receipt/inv_6ak9uz7fic
5. The objection the system filed against its own targeting, before anyone else could — https://miscsubjects.com/a/outreach-machinery#disc-obj-205


---

# The rule set, the model's clause-by-clause reasoning, and the action it authorised, stored as one replayable record

slug: auditable-reasoning · https://miscsubjects.com/a/auditable-reasoning · tags: governance, adjudication, decision-constitution, front-door · updated 2026-08-01T23:55:12.171Z

## The primitive, in one paragraph

Auditable reasoning is not a model that explains itself. It is a system of record in which four things are the same inspectable object: the exact rules a model was placed under, the model's stated reasoning bound step-by-step to those rules, the evidence it used and — just as loudly — the evidence it was never given, and the verdict with what would change it. Preserve that object for every consequential call, run several independent models against the same pinned rules, refuse to act when their derivations diverge, and you have converted "AI governance" from policy documents surrounding a model into the model's own inspectable operating procedure.

This page states the mechanism exactly, shows one real governed finding, and links the worked cases: [a statute](https://miscsubjects.com/a/adjudication-eu-ai-act-article-50), [a contract dispute](https://miscsubjects.com/a/adjudication-contract-service-credit), [a medical coverage claim](https://miscsubjects.com/a/adjudication-medical-prior-auth), [an image-bearing record](https://miscsubjects.com/a/attested-finding-image-record-action).

## The one sequence to understand

Three independent models, each called fresh with no memory, receive the identical governing prompt and the identical record. All three reach the **same verdict**. Their **controlling clauses differ**. The gate **refuses to authorise** — and you can open every raw payload and check exactly why each model got there. That sequence is the whole thing. It is not a consensus panel (those count votes), not an observability trace (those log calls), not a compliance dashboard (those assert coverage). It is a governed decision you can take apart at any joint. Both worked cases below end on exactly that refusal.

## What an ordinary agent trace shows, and what this shows

A typical published trace is: prompt → tool calls → output. Useful for debugging, useless for accountability, because the questions that matter are unanswerable from it: which rule authorized this? what evidence supported it? what did the model never see? why not the other action? was the claimed outcome verified?

A governed record here answers each one as a field:

```
controlling clauses → known facts (each with its source record) → unknown facts (and what
they would change) → proposed action → rejected alternative (named, with why) → expected
result → failure response → records absent → verification required → verdict → what would
flip it
```

The difference is not verbosity. It is formal correspondence between governing rules, stated reasoning, and machine action — one object a reader can interrogate at any joint.

## The constitution

The rules are not a paragraph of encouragement. Every consequential call runs under the **Decision Constitution** (`decision-constitution@1.1.0`), a versioned object the live system returns verbatim:

```bash
curl -s -X POST https://miscsubjects.com/api/dispatch \
  -H 'content-type: application/json' \
  -d '{"key":"DECISION_CONSTITUTION","body":""}'
```

[[embed:source:s1]]

Its clauses, compressed: the rules given are law for this call and refusal is a recorded right (C2); stop on uncertainty rather than answer fluently (C3); no decoration, assume the reader is harmed by anything inexact (C4); every output is an isolated logical proof (C5); a seven-step numbered reasoning protocol in which every step names its controlling clause (C6); a mandatory list of the records a competent reviewer would have expected that were NOT supplied (C7); a structured decision record ending in a verdict (C8); nothing is called done without the record proving it (C9); no repeated failing retries (C10); a genuine rule conflict is named, never silently resolved (C11).

The constitution travels **inside the request payload**. The preserved object therefore carries the exact law its model was under — the version, not a paraphrase — which is what makes a year-later audit possible without trusting anyone's memory.

## Lineage: the reasoning columns became the ledger

This is not a fresh idea dressed in new machinery. It is the oldest idea in this system.

In the owner's original build — June 2026, running on a spreadsheet — every model turn was governed by numbered clause law (A1, the master law; A2, the reasoning protocol). The model was required to emit a numbered REASONING block before any reply or tool call: which clauses apply, what is known, what is unknown, what it is about to do, why not the alternative, what it expects, what it will do if wrong — ending in a DECISION line. The runtime then stripped that block from the user's reply and wrote three columns on every loop: the raw model output, the raw tool call, the tool result.

Three audit columns in a spreadsheet. That was the ledger, before the ledger. The protocol required verification before any confirmation — a write was not "done" until a read-back proved it — and clause insertion into the law itself went through a tool that preserved everything already there. The original protocol is preserved verbatim, contacts scrubbed, as a guidebook in this repository: `prompts/original-decision-protocol-2026-06.md`.

What the present system adds is generality and adversarial depth: hash-pinned rule sets, complete gateway payloads instead of output columns, several model families instead of one, a deterministic seal instead of a single verdict, receipts a stranger can open instead of columns an owner can read. The primitive did not change. Its proof surface did.

## One real governed finding

Below is a complete finding from the contract case — the anatomy above, produced by a live model under the constitution, verbatim including its imperfections:

[[embed:source:s2]]

Note the parts an ordinary trace never contains: the model recites the conditions it operates under and the hashes that pin them; it lists what it was **not** given — the signed agreement, the claim email's provable transmission date, any waiver — before reasoning at all; each step names its clause; the strongest alternative (the customer deserves the credit because the outage was real) is named and rejected on clause grounds; and the finding states what would flip it.

## The gate, and why unanimity is not enough

Both new cases ended the same instructive way: three model families, three DENY verdicts — and the deterministic seal returned **ESCALATE**, not APPROVE.

[[embed:source:s3]]

The refusal has two grounds. Caller-supplied findings run in a mode that can never authorise — only records the sealer loads itself can. And the clause citations diverged across seats: same conclusion, different derivations. The gate treats that as unresolved because it is: two reasoners who agree for different stated reasons have not checked each other, they have coincided. Majority voting cannot see this. Derivation-level comparison can, and it is only possible because the constitution forces every finding into a shape where derivations are comparable.

## The same chain, four evidence burdens

| case | rules | artifact | panel | outcome |
|---|---|---|---|---|
| [EU AI Act, Article 50](https://miscsubjects.com/a/adjudication-eu-ai-act-article-50) | statute, verbatim, pinned | a deployed system's description | five seats | receipted adjudication; the probe report measures each seat's error rate |
| [contract service credit](https://miscsubjects.com/a/adjudication-contract-service-credit) | six agreement clauses, hashed | monitoring export + late claim, synthetic and labeled | three families | unanimous DENY, sealed ESCALATE on derivation divergence |
| [medical prior authorization](https://miscsubjects.com/a/adjudication-medical-prior-auth) | payer policy, hashed, with its own not-clinical-judgment clause | submitted clinical note, synthetic and labeled | three families | unanimous DENY, each seat naming the record that would flip it, sealed ESCALATE |
| [image-bearing record](https://miscsubjects.com/a/attested-finding-image-record-action) | pinned rule set | hashed synthetic radiograph + record | four seats + recorded adversary | the silent pixel loss and the false-confidence event, preserved |

One machinery. What changes per case is the evidence burden, the consequence of being wrong, and therefore — under [logical economics](https://miscsubjects.com/a/logical-economics) — how much reasoning the question is worth and how tight the error bound must be before anything acts.

## The honest limits

The constitution constrains stated reasoning, not hidden computation — the defensible object is the model's stated decision rationale plus its complete execution trace, and this page claims nothing about chain-of-thought faithfulness. Findings differ in format across families, so clause extraction has edge cases, visible in the case pages. The fixtures in the two new cases are synthetic and say so inside the artifact. And no bound assembly has ever reached APPROVE — the gate's sensitivity is proven; its acceptance path is not yet exercised by a real panel. Every one of these belongs to a reader before it belongs to a defense.

## Sources

1. The Decision Constitution, versioned, returned verbatim by the live system — https://miscsubjects.com/api/dispatch
2. @cf/moonshotai/kimi-k2.7-code — one complete governed finding (contract case) — https://miscsubjects.com/receipt/inv_ns9ttj12at
3. The seal that refused a unanimous panel — https://miscsubjects.com/receipt/inv_hfyd7y2num

