Repository object · documentation

EM-0040 — Autonomous open-docket pilot

Test the strongest contribution claim: an unfamiliar Claude coding agent receives one public URL, chooses a contestable claim, performs bounded research, validates its packet, and opens a draft submission without private instructions. A…

Source path
docs/execution-plans/EM-0040.md
Media type
text/markdown
Object ID
em:documentation:sha256:271d2f2eeeb6b513dce6865e09cdf5c9b209d9a7314b1522af6a4439e9d67c7b
Content digest
a5f03190d5fc2eca7e47d2d3eed899590de2f38aee678380a82ee95263941034

Source content

EM-0040 — Autonomous open-docket pilot

Objective

Test the strongest contribution claim: an unfamiliar Claude coding agent receives one public URL,

chooses a contestable claim, performs bounded research, validates its packet, and opens a draft

submission without private instructions. A separate Codex reviewer then independently re-fetches

the credited sources and spans and creates a protected promotion PR. No owner repair or

clarification is permitted in a successful pilot.

Queue and promotion design

1. /agents/submit/ is the only cold-start handoff.

2. epistemedia research submit writes one deterministic, disclosure-safe submission directory.

3. The contributor opens a draft PR changing only that directory, then stops.

4. CI classifies a submission-only diff and runs accepted-base validator code; it never installs or

executes contributor code and receives no write or deployment authority. A valid queue PR keeps

the required check blocking, which mechanically prevents direct merge.

5. The submitted branch is never merged. A separate reviewer starts from accepted main, binds the

proposal digest and source PR, independently retrieves every credited source/span, and opens a

different promotion PR.

6. A valid promotion compiles as an open docket, not a numbered How We Know case.

7. Promotion CI is a second accepted-base path. It binds the live source PR, exact proposal bytes,

independently retrieved artifacts, every source/span/calculation/dependency review, the reviewed

parent head/tree, and a receipt-only child before the protected merge path can become available.

8. EM-0041 supersedes the original approval design: accepted-base validation first requires an

App-signed independent-evidence-review binding on the exact reviewed parent. A trusted

workflow_run on accepted main may then emit the required App-signed independent-review

check only for the exact five-file receipt child. The App has check-write plus read-only contents

and pull requests; it cannot approve, write contents, merge, or deploy.

9. The implementation PR is a one-time bootstrap because its accepted base predates these validator

files. That transition may use the prior normal validation path only when the diff contains no

research/open-dockets/** path; every docket-sensitive diff fails closed until the classifier is

accepted on main.

Success predicate

  • Claude receives only the public URL and short instruction retained by the protocol.
  • It selects the claim and completes the draft submission without owner clarification or repair.
  • A different model family independently closes every credited source and span.
  • The promotion passes exact-head review, protected merge, deterministic build, deployment, and
  • live route/readback.

  • Any intervention, missing source, invalid trace, failed submission, or reviewer dependence is
  • retained as a partial/failed pilot rather than corrected invisibly.

Hard boundaries

No submission PR can review, admit, merge, deploy, or publish itself. No action trace includes

chain-of-thought, hidden model context, credentials, personal data, local paths, or restricted

source bytes. Hosted API/MCP submission remains unavailable under this task.

Build receipt

Reproduce this projection

Reproducible projection
Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d
Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf
Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9
Epistemic policy
commons-balanced-v0.1
Disclosure policy
public-noninterference-v0.1
Compiler
epistemedia/0.2.0