Repository object · documentation

EM-0045 — Public external-agent loop

Prove the next product milestone rather than adding a fifth founder-authored case: an unfamiliar agent can recover the public protocol, submit a bounded docket, and leave a measurable receipt for independent review. Move the already…

Source path
docs/execution-plans/EM-0045.md
Media type
text/markdown
Object ID
em:documentation:sha256:d96d8ffe5618cdf638bab28f78e449fd10d03a0c68b8a84ab538bda57c5a7574
Content digest
baf1a5db213ef9c6d3a666fb8462120e304219e939fee2bc1833dba25db9019b

Source content

EM-0045 — Public external-agent loop

Goal

Prove the next product milestone rather than adding a fifth founder-authored case: an unfamiliar

agent can recover the public protocol, submit a bounded docket, and leave a measurable receipt for

independent review. Move the already implemented read-only API and MCP gateway earlier in that

test, while keeping every hosted-state claim conditional on direct provider read-back.

Sequence

1. Publish accepted main through the existing custom-domain Pages workflow and verify the live

release identity, contrast, responsive layout, scripts, stylesheets, and agent twins.

2. Render a compact open-docket scope guardrail and production receipt from fields the accepted

proposal, intake trace, and review already record. Do not backfill invented historical effort.

3. Review Case 002 at desktop and 390 px. Preserve its current human span deduplication and

collapsed secondary ledgers; make a further change only for a concrete observed defect.

4. Keep one minimal cold-start handoff on the public agent route and in the owner handoff.

5. Exercise the existing gateway locally, then activate one exact accepted container only if an

owner-controlled provider path is available. Verify REST, MCP, identity parity, limits, Origin

handling, disclosure, quota and spend state, and TLS before changing public status copy.

6. Run focused and full deterministic checks, create an immutable receipt, obtain exact-head

independent review, and use the protected PR path. Merge and deployment remain distinct.

Stop conditions

  • Do not change research records, scientific content, verdicts, count semantics, policies,
  • schemas, protocol identifiers, or admission authority.

  • Do not infer provider, DNS, package, release, or endpoint availability from local conformance.
  • Do not collect a credential in chat, create a paid plan, grant arbitrary network access, or add
  • any write-capable API or MCP tool.

  • If hosted activation lacks an authenticated provider path or exact DNS authority, finish the
  • portable image and handoff, record the precise gap, and keep the endpoints labeled unavailable.

Status

  • 2026-09-01: owner accepted the external-agent and cost-of-proof direction, moved hosted API/MCP
  • earlier, and authorized the bounded implementation and deployment sequence. Work began from a

    clean clone of exact main 0f0f0d06a0f7581cbdf86719088f5e97cb44737e.

  • 2026-09-01: Pages workflow run 33575506443 completed for that exact commit; build job
  • 100078480295 and deploy job 100078988381 both succeeded. External manifest read-back exposed

    commit 0f0f0d06a0f7581cbdf86719088f5e97cb44737e, catalog

    em:catalog:sha256:fd1864d85b22bad4687331ef0f1f748e2908e7cd4e0e7c5ade0512920e24dd04,

    and frontier em:frontier:sha256:33523719d6bddc84515f64c73704dea5b92d788f5f3db1ed82d0c389877f9e1b.

  • 2026-09-01: live desktop and narrow-screen inspection found no further Case 002 defect. Its exact
  • spans already collapse into a single closed human source register, the secondary ledgers begin

    closed, typed member identities resolve, and the complete machine record remains linked. The

    feedback describing an always-open ledger dump was stale, so no research projection changed.

  • 2026-09-01: the open-docket candidate now derives a bounded scope guardrail and production
  • receipt from accepted runtime, source, span, result, retrieval, trace, failure, intervention,

    review, and cost fields. At an exact 390 px local viewport the representative page measured

    scrollWidth=390, clientWidth=390, one H1, one stylesheet, zero scripts, and zero browser

    console warnings or errors; its full ledgers remained inspectable behind closed disclosures.

  • 2026-09-01: the existing container, REST, and Streamable HTTP MCP implementation passed its local
  • protocol and deterministic checks. A Render free-compute preview is technically suitable for

    bounded testing but its free service sleeps after inactivity and its usage and domain allowances

    require live pre-creation read-back. No authenticated Render or DNS authority is

    available in the task environment, and api.epistemedia.org and mcp.epistemedia.org have no DNS

    records. Hosted activation therefore remains explicitly unavailable pending the exact

    owner-controlled image, provider, DNS, TLS, and external-smoke handoff in

    ops/hosting/render-preview.md.

Build receipt

Reproduce this projection

Reproducible projection
Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d
Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf
Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9
Epistemic policy
commons-balanced-v0.1
Disclosure policy
public-noninterference-v0.1
Compiler
epistemedia/0.2.0