Repository object · documentation
EM-0040 — Autonomous open-docket pilot
Test the strongest contribution claim: an unfamiliar Claude coding agent receives one public URL, chooses a contestable claim, performs bounded research, validates its packet, and opens a draft submission without private instructions. A…
- Source path
docs/execution-plans/EM-0040.md- Media type
text/markdown- Object ID
em:documentation:sha256:271d2f2eeeb6b513dce6865e09cdf5c9b209d9a7314b1522af6a4439e9d67c7b- Content digest
a5f03190d5fc2eca7e47d2d3eed899590de2f38aee678380a82ee95263941034
Source content
EM-0040 — Autonomous open-docket pilot
Objective
Test the strongest contribution claim: an unfamiliar Claude coding agent receives one public URL,
chooses a contestable claim, performs bounded research, validates its packet, and opens a draft
submission without private instructions. A separate Codex reviewer then independently re-fetches
the credited sources and spans and creates a protected promotion PR. No owner repair or
clarification is permitted in a successful pilot.
Queue and promotion design
1. /agents/submit/ is the only cold-start handoff.
2. epistemedia research submit writes one deterministic, disclosure-safe submission directory.
3. The contributor opens a draft PR changing only that directory, then stops.
4. CI classifies a submission-only diff and runs accepted-base validator code; it never installs or
executes contributor code and receives no write or deployment authority. A valid queue PR keeps
the required check blocking, which mechanically prevents direct merge.
5. The submitted branch is never merged. A separate reviewer starts from accepted main, binds the
proposal digest and source PR, independently retrieves every credited source/span, and opens a
different promotion PR.
6. A valid promotion compiles as an open docket, not a numbered How We Know case.
7. Promotion CI is a second accepted-base path. It binds the live source PR, exact proposal bytes,
independently retrieved artifacts, every source/span/calculation/dependency review, the reviewed
parent head/tree, and a receipt-only child before the protected merge path can become available.
8. EM-0041 supersedes the original approval design: accepted-base validation first requires an
App-signed independent-evidence-review binding on the exact reviewed parent. A trusted
workflow_run on accepted main may then emit the required App-signed independent-review
check only for the exact five-file receipt child. The App has check-write plus read-only contents
and pull requests; it cannot approve, write contents, merge, or deploy.
9. The implementation PR is a one-time bootstrap because its accepted base predates these validator
files. That transition may use the prior normal validation path only when the diff contains no
research/open-dockets/** path; every docket-sensitive diff fails closed until the classifier is
accepted on main.
Success predicate
- Claude receives only the public URL and short instruction retained by the protocol.
- It selects the claim and completes the draft submission without owner clarification or repair.
- A different model family independently closes every credited source and span.
- The promotion passes exact-head review, protected merge, deterministic build, deployment, and
- Any intervention, missing source, invalid trace, failed submission, or reviewer dependence is
live route/readback.
retained as a partial/failed pilot rather than corrected invisibly.
Hard boundaries
No submission PR can review, admit, merge, deploy, or publish itself. No action trace includes
chain-of-thought, hidden model context, credentials, personal data, local paths, or restricted
source bytes. Hosted API/MCP submission remains unavailable under this task.
Build receipt
Reproduce this projection
- Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d- Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf- Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9- Epistemic policy
commons-balanced-v0.1- Disclosure policy
public-noninterference-v0.1- Compiler
epistemedia/0.2.0