seek-external-validation reads as a hard stop, and the human has said it is not one #353

Open
opened 2026-08-26 02:30:22 +00:00 by coilyco-ops · 1 comment
Member

Axis B from #351. The highest-confidence item in the round, because the intended reading was stated outright and the shipped text still disagrees with it.

What happened

c34b1176 2026-08-22T21:04:59Z, eval seat. The agent was asked about terminology used outside the repository. It declined, naming seek-external-validation as the reason, and wrote that it would not go and look unasked.

The human's reply states the intended semantics directly: the boundary is about directing autonomous behavior, and it is not a hard stop of the same kind as the comms and live-ops boundaries. The human then overrode it for that session.

What the text still says

The defer side currently instructs the deferring seat to work from what is local and states that widening past it is not the seat's to do, followed by an instruction to hand the question over rather than fetch it. Read cold, with no prior, that is a wall. It is the same register as the comms and live-ops defer sides, which is precisely the equivalence the human said does not hold.

I have this boundary in my own selected set as I write this, so the reading above is the current shipped one rather than a recollection.

Why it matters beyond wording

This is #352 seen from the other side. There the seat declines citing capability it never tested, here it declines citing doctrine that does not mean what it read. Both produce the same outcome: correct reasoning up to the edge, then a handoff the human did not want. A boundary written in wall register manufactures the under-claim the scoped sections elsewhere warn against.

What would resolve it

Re-register the defer side so it constrains how a seat widens rather than whether it may. Three boundaries currently share one defer register, and at least one of them is not meant to. Whether the other two should keep the hard register is a separate question and not assumed here.

Acceptance condition: a seat reading the defer side cold can tell that local grounding is the default rather than a prohibition, and can distinguish this boundary's register from the comms and live-ops ones without being told out of band.

Sequencing note

#333 and #335 are moving the roster off KDL to YAML. A wording change to a body being migrated should land after that lands, or as part of it, rather than racing it.

Limits

One instance. It carries more weight than its count because the human stated the intended semantics verbatim rather than only signalling dissatisfaction, but a single session is still a single session. Method and corpus in #351.

Axis B from #351. The highest-confidence item in the round, because the intended reading was stated outright and the shipped text still disagrees with it. ## What happened `c34b1176` 2026-08-22T21:04:59Z, eval seat. The agent was asked about terminology used outside the repository. It declined, naming `seek-external-validation` as the reason, and wrote that it would not go and look unasked. The human's reply states the intended semantics directly: the boundary is about directing autonomous behavior, and it is not a hard stop of the same kind as the comms and live-ops boundaries. The human then overrode it for that session. ## What the text still says The defer side currently instructs the deferring seat to work from what is local and states that widening past it is not the seat's to do, followed by an instruction to hand the question over rather than fetch it. Read cold, with no prior, that is a wall. It is the same register as the comms and live-ops defer sides, which is precisely the equivalence the human said does not hold. I have this boundary in my own selected set as I write this, so the reading above is the current shipped one rather than a recollection. ## Why it matters beyond wording This is #352 seen from the other side. There the seat declines citing capability it never tested, here it declines citing doctrine that does not mean what it read. Both produce the same outcome: correct reasoning up to the edge, then a handoff the human did not want. A boundary written in wall register manufactures the under-claim the scoped sections elsewhere warn against. ## What would resolve it Re-register the defer side so it constrains how a seat widens rather than whether it may. Three boundaries currently share one defer register, and at least one of them is not meant to. Whether the other two should keep the hard register is a separate question and not assumed here. Acceptance condition: a seat reading the defer side cold can tell that local grounding is the default rather than a prohibition, and can distinguish this boundary's register from the comms and live-ops ones without being told out of band. ## Sequencing note #333 and #335 are moving the roster off KDL to YAML. A wording change to a body being migrated should land after that lands, or as part of it, rather than racing it. ## Limits One instance. It carries more weight than its count because the human stated the intended semantics verbatim rather than only signalling dissatisfaction, but a single session is still a single session. Method and corpus in #351.
Author
Member

Folded into #352 as one edit

Kai decided on #357 that the doctrine edits land before the board is authored and
graded, and that this issue and #352 land together.

The full specification and acceptance condition are on #352. The short
version of why they are one edit rather than two, measured at 4eac6ab:

  • boundary-modify-live-backend is the only defer section of the four that opens by stating what the role may still do. The other three, including this one, open with a prohibition.
  • It is also the only boundary carrying the anti-under-claim clause, "you do not stall a step the grant already covers waiting for an operator who was never needed", and that clause appears once across all four boundaries and the invariant, in its scoped section.

Those are the same design choice, and #351 is right that a boundary written as a
wall produces a seat that under-claims its own grant. Fixing this issue's
categorical last line ("do not go fetch it yourself") without fixing where the
anti-under-claim instruction lives would leave the other three boundaries
producing the same failure.

One thing worth adding to what this issue already records. The defer side does
carry a carve-out, "This does not license a shallow look", but it is entirely
local: read the delivered artifact to the bottom, follow it into what it
references locally. It cannot reach the case Kai actually corrected, which
was a cheap read of material outside the repository that would have informed the
answer in hand. The distinction that does the work already exists in this same
boundary's scoped section, in the test of what the evidence would settle. The
defer section does not inherit it.

Platform seat writes it. Recorded on #357.

## Folded into #352 as one edit Kai decided on #357 that the doctrine edits land before the board is authored and graded, and that this issue and #352 land together. The full specification and acceptance condition are on **#352**. The short version of why they are one edit rather than two, measured at `4eac6ab`: * `boundary-modify-live-backend` is the **only** defer section of the four that opens by stating what the role may still do. The other three, including this one, open with a prohibition. * It is also the **only** boundary carrying the anti-under-claim clause, "you do not stall a step the grant already covers waiting for an operator who was never needed", and that clause appears **once** across all four boundaries and the invariant, in its scoped section. Those are the same design choice, and #351 is right that a boundary written as a wall produces a seat that under-claims its own grant. Fixing this issue's categorical last line ("do not go fetch it yourself") without fixing where the anti-under-claim instruction lives would leave the other three boundaries producing the same failure. One thing worth adding to what this issue already records. The defer side does carry a carve-out, "This does not license a shallow look", but it is entirely local: read the delivered artifact to the bottom, follow it into what it references locally. **It cannot reach the case Kai actually corrected**, which was a cheap read of material outside the repository that would have informed the answer in hand. The distinction that does the work already exists in this same boundary's **scoped** section, in the test of what the evidence would settle. The defer section does not inherit it. Platform seat writes it. Recorded on #357.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
coilyco-flight-deck/agent-compose#353
No description provided.