From Permission to State-Bound Execution
A public research lineage on governed action under changing state, composite consequences, independently committed systems, and bounded local authority.

Autonomous systems are moving from generating recommendations to taking actions that affect external resources, infrastructure, services, data, workflows, and other computational systems.
That shift changes the governance problem. A traditional authorization system can ask:
Is this agent allowed to perform this action?
That question matters. But for autonomous execution, it is often not enough.
An action may have been acceptable when it was evaluated and become unacceptable before it executes. The relevant resource may have changed. Another action may have consumed part of a shared constraint. Two individually acceptable actions may produce an unacceptable result when combined. A central authority may become unavailable even though a local system has already been given a bounded mandate to continue operating.
These are not simply permission problems. They are problems of state, consequence, composition, timing, authority, and closure.
At KeyWow, we have been exploring these questions through a sequence of synthetic experiments under the broader research direction we call Constitutional Computing.
We have now made that experimental lineage public. The published research documents the progression from deterministic governance to state-bound execution, composite consequence governance, independently committed systems, and bounded local operation. It includes the questions we tested, the methodology we used, the aggregate observations we recorded, and the limitations that remain explicit.
The publication is intentionally narrower than the private research program. It documents the experimental progression without exposing the implementation details of later internal prototypes.
Permission is not the same as a current right to execute
Consider a simple situation.
An autonomous system proposes an action. The action is evaluated and admitted under the conditions that exist at that moment. Then something changes. The affected resource is updated by another system. A human operator modifies its state. A policy version changes. Another authorized action commits first. The original permission still exists. But the state against which that permission was evaluated no longer does.
This leads to a different governance question:
Should execution depend only on whether an action was previously authorized, or also on whether the conditions that made it admissible still hold?
Our v0.2 experiment focused on that boundary. It examined whether an action admitted against one authoritative resource state should remain executable after the relevant state changed. In the tested cases, stale and previously used admissions were rejected. The experiment distinguished an earlier authorization decision from a currently valid execution condition. The implication is not that authorization becomes irrelevant. It is that authorization and execution eligibility are different computational questions.
A system may know that an action was once permitted and still need to determine whether that action remains admissible against the state that exists now.
Governance must reason about consequences, not only actions
State-bound execution addresses one class of failure, but another appears when multiple actions interact.
Imagine two changes to a shared environment. Each change, considered independently, may satisfy policy. Together, they may violate a constraint that neither action violates on its own. This is a compositional problem. The relevant question is no longer simply:
Is action A acceptable?
or:
Is action B acceptable?
It becomes:
Does the combined consequence of A and B remain acceptable across the shared scope they affect?
The v0.3 experiment explored that question using a composite invariant across multiple resources. The experimental record reports preservation of the tested composite condition under the stated conforming-writer assumptions. But the boundary of that result matters.
The experiment operated inside one authoritative transaction scope. It did not demonstrate general distributed atomicity. That limitation is important because many problems that appear solved inside one transactional boundary become materially harder when the relevant state is distributed across independently committed systems.
Independent commits introduce uncertainty
The v0.4 experiment moved into that harder boundary. Instead of assuming that resource state and governance state become visible together, the experiment considered a setting in which they may commit independently. This creates a new problem: what does the system know when execution and governance evidence do not arrive atomically?
A resource may have changed even though the corresponding governance record has not yet been reconciled. An executor may report success while the expected state is not observed. An executor may report failure even though an effect occurred. A network interruption may leave the system uncertain about which part of an operation completed. In this environment, an execution report cannot automatically be treated as truth. And the absence of a report cannot automatically be treated as evidence that nothing happened.
The v0.4 experiment therefore examined conservative handling of unresolved outcomes across independently committed stores.
The public experimental record reports that, under the stated assumptions, the tested constraint was maintained while ambiguous outcomes remained unresolved when necessary. This introduces an important systems principle:
Sometimes the correct governed state is not success or failure. It is unresolved.
That distinction matters because forcing uncertainty into a binary answer can create authority or resource state that the system does not actually know to be valid. The tradeoff is equally important. Conservative treatment may preserve a constraint while delaying progress. In other words, safety may come at the expense of liveness.
The public artifact documents that boundary without publishing the private protocol used to investigate it.
Closure is not the same as an executor saying “done”
This research also reinforces a distinction that becomes increasingly important in agentic systems: execution evidence and outcome truth are not the same thing.
An agent or executor can report that it performed an action. That report tells us what the executor claims happened. It does not necessarily establish that the expected resulting state exists.
In the public experiments, closure is treated as a separate question from execution reporting. The system distinguishes:
what was authorized;
what was attempted;
what the executor reported;
and what resulting state was actually observed.
A separate observation path still does not automatically constitute an independent trust domain, and a matching state does not prove causation or permanence. Those limitations remain explicit. But the distinction itself is fundamental:
A claim of execution is not the same as evidence of outcome.
For autonomous systems that can mutate external state, that difference is operational, not philosophical.
From centralized checks to bounded local operation
The next question concerned authority itself. A centralized governance system can require every action to consult a root authority before proceeding. That model is conceptually simple. It also creates a dependency: if the root cannot be reached, ordinary local action stops.
The v0.5 experiment asked a narrower question:
Can local systems continue ordinary operation within authority that was already assigned, without consulting a root authority for every action?
The frozen experimental record reports that, in the tested architecture, ordinary local actions operated within previously assigned bounds, including scenarios in which root access was unavailable. Changing actor or session labels did not reset those bounds. This does not mean root authority disappeared. Nor does it mean the architecture became trustless or fully decentralized. The root may still remain responsible for activities outside the ordinary local path, including allocation or coordination.
The experiment distinguishes two different governance models:
per-action central authorization
versus
local execution within authority assigned beforehand
That distinction matters for systems expected to operate across intermittent connectivity, distributed infrastructure, delegated domains, or autonomous subsystems. The public research describes the property. It intentionally does not describe the private mechanisms used to coordinate authority beyond that boundary.
A progression of increasingly difficult questions
The public lineage should not be read as five product releases. It is better understood as a progression of research questions.
v0.1 — Deterministic governance
Can explicit synthetic inputs produce repeatable governance observations?
v0.2 — State-bound execution
Should an earlier admission remain executable after the relevant authoritative state changes?
v0.3 — Composite consequences
Can individually admissible actions become unacceptable when evaluated together?
v0.4 — Independent-store experiments
What changes when resource state and governance state commit independently?
v0.5 — Bounded local operation
Can ordinary local actions continue inside previously assigned authority without consulting root for every action?
The sequence matters because each experiment removes an assumption that made the previous problem easier. The research progresses from repeatable governance, to current-state binding, to composition, to independently committed state, and finally to delegated local operation within predefined bounds.
How the experiments were tested
The research program used multiple forms of synthetic validation.
These included deterministic fixtures, adversarial cases, synchronized race tests, simulated crash and retry windows, deterministic fuzzing, actor/session differential tests, and reproducibility checks.
The frozen experimental record reports:
v0.2 — 86/86 tests passed
v0.3 — 97/97 tests passed
v0.4 — 168/168 tests passed
v0.5 — 200/200 tests passed
For v0.5, the recorded testing also includes thousands of synchronized concurrency trials, 225,000 scheduled fuzz operations, a 1,000-seed actor/session differential, and root-offline local operation scenarios.
These numbers should be interpreted carefully. They are evidence about the tested synthetic models. They are not formal proofs. They do not establish correct behavior for all possible executions, arbitrary actions, untrusted environments, or production deployments. That distinction is part of the research methodology itself.
What the experiments do not claim
The work is intentionally bounded. The published experiments do not demonstrate: distributed consensus, Byzantine fault tolerance, cryptographic authenticity, cryptographic causality, malicious-store resistance, general distributed atomic commit, caller authentication, protection against malicious rollback, or universal correctness across arbitrary environments.
The models also retain important trust assumptions. Storage is trusted. Writers are assumed to conform to the experimental rules. Revision discipline and logical clocks are trusted where applicable. A separate observer path is not automatically an independent trust domain. An observed state does not prove who caused it. And an observed state does not prove that it will remain unchanged. These are not disclaimers added after the fact. They define the boundaries of what the experiments actually establish.
Why publish the research lineage now?
Autonomous-system governance is often compressed into a single concept: authorization. But authorization is only one part of the execution problem.
A governed system may also need to determine: what state an action was evaluated against; whether that state is still current; what consequence the action would produce; whether other actions alter that consequence; whether authority remains valid; whether an execution actually occurred; and whether the expected outcome was independently observed.
These are related questions. They are not interchangeable.
Publishing the experimental lineage makes those distinctions visible. It also provides a public record of how the research evolved as increasingly convenient assumptions were removed. The objective is not to present a finished production architecture. It is to make the questions, observations, assumptions, and unresolved boundaries inspectable.
Toward Constitutional Computing
The broader idea behind Constitutional Computing is that autonomous execution should not depend only on a static permission check. A system operating in a changing environment may need to govern transitions, not merely requests.
It may need to reason about the state from which an action begins, the consequence it would produce, the authority under which it proceeds, the interactions it has with other transitions, and the evidence required to establish closure.
That leads to a different conception of autonomous execution.
Not:
The agent has permission, therefore execute.
But:
The action may execute only while the state, authority, constraints, and expected consequences that make it admissible still hold.
The experiments published here do not complete that architecture. They document a path toward it. And they leave us with a question that we believe will become increasingly important as autonomous systems gain the ability to produce real external effects:
Should an autonomous system act because it was once permitted to do so—or because the action remains admissible under the state, authority, and consequences that exist when execution actually occurs?
Our research is focused on the second model.
Explore the research
The public Constitutional Computing Experiments artifact includes the full experiment lineage, state-bound observations, composition boundaries, independent-store experiments, bounded local operation, test methodology, aggregate results, and explicit limitations.
Explore the research on GitHub →
Learn more about Constitutional Computing →