A backward-compatible MINOR release.
The architecture adds approval-to-effect continuity, governed self-improvement and durable evidence contracts. Central decision authority, distributed cognition, shared evidence, independent judging and gated execution remain canonical.
1. Authority must survive every transformation
A human can approve operation A while parsing, continuation state, default insertion, recovery or retry later turns it into B. The new approval-to-effect contract resolves the complete operation, renders the approval view from the same canonical descriptor, binds principal, task, scope, expiry and digest, then reconstructs the current operation at use time. Material change means deny or re-approve. Approval is consumed atomically with effect release.
Loopjacking reports controlled reproductions across selected versions and a negative control with exact per-call binding. The sample is purposive and does not estimate ecosystem prevalence. Harness uses the result as comparative evidence for authorization continuity, not as a universal product claim.
Authority is now evaluated as an executable path: agent identity → direct entitlement → reachable resource → delegated credential → indirect entitlement → runtime sequence → effect. Full-path isolation covers the credential broker, egress, filesystem, setup/install phases, cumulative session budgets and external audit evidence. A secure-looking container or a reviewed entitlement list is incomplete if the composed path can still escape the intended boundary.
2. Optimize the harness without absorbing its controls
Team organization is now governed non-weight state. Roles, conversational phases, participation, information flow, challenge and synthesis can be learned, versioned and qualified. Self-Organizing Agent Teams supports adaptive distributed cognition, but learned organization does not grant runtime authority or own promotion.
Harness evolution gains edit budgets, evolution memory, a critic, noise and cost gates, pruning, protected surfaces, held-out evaluation and rollback. RRSI v2 supplies benchmark evidence for regularization; its OOD gains are smaller than evolve-set gains and remain configuration bounded.
Harness-Zero shows that some harness-induced capability can be transferred into model weights. The control boundary is explicit: authorization, policy decisions, segregation of duties, evidence integrity, data boundaries and kill controls stay independently enforceable unless equivalent protection is separately demonstrated. Distilled behavior is not independent control.
Cheap surrogate evaluators may guide dense search, but authoritative promotion evidence remains separate. Generated skills and environments preserve outcome oracles, behavioral rubrics, provenance and independent evaluation lineage. The optimizer cannot edit its own policy engine, held-out data, verifier authority, audit integrity or rollback path.
3. Durable evidence, verification and the reading shortlist
Raw session truth and model-facing context are now separate surfaces. Evidence graphs retain source observations, transformations, identity-resolution uncertainty, freshness and provider-specific records. Graph inference informs synthesis and judging; it never grants action authority. Incident closure now requires evidence hold, attribution, root cause, implemented correction, retest, regression/eval update and verified learning—not merely a closed ticket.
The release also extends economic depth with underwritable action/effect evidence and shared-dependency accumulation risk; adds threat-to-control interruption and exposure-ownership lifecycles; and strengthens FRIA/use-context validation and SOC consolidation assurance. Framework coverage, vendor claims and platform consolidation remain inputs, not proof of operating effectiveness.
Reading shortlist: 18–25 September
RRSI: Regularized Recursive Self-Improvement of Agent Harnesses — 21 September; v2 on 23 September. Eight benchmarks; reported gains up to 14.1 points on the evolve split, 4.7 on five OOD benchmarks and 30% fewer policy tokens. Preprint and configuration bounded. New control pattern: regularize proposals and selection; keep protected authority outside the optimizer.
Self-Organizing Agent Teams Learn to Reason Together — 19 September. Reported five-benchmark average 66.7%, versus 48.8% for the strongest member and 59.0% for an oracle router; demonstrability correlates with gain. Small fixed rosters, benchmark domains and post-hoc correlation limit generalization. New orchestration pattern: version organization while retaining centralized authority.
Harness-Zero: Harness Distillation via Agent-as-Harness — 21 September. Reported macro success 23.3%→44.3% and 82.3% recovery across 28 behavior patterns. No independent production assurance or control-equivalence evidence. New optimization pattern with concern: distill capability scaffolding, not independent enforcement.
Release notes and complete source map · Architecture changelog · Previous v1.1.0 release.