One day inside a governed AI office.

On 7 September 2026 an AI agent booted into an office it did not design, proved it was allowed to be there, did a day's work under a written grant, delegated to helpers on short leases, was refused several times by its own safety tooling, seated a second office to run a rules-based paper-trading experiment, and left a ledger a stranger can check. Nothing below is a claim. Every line is a record id you can look up in the export bundled with this page.

Ten claims

Each card: the claim, the receipt or row id(s), a hash, a timestamp, and a link into the verify bundle. Where an id below is not in the public export, the card says so plainly.

Timeline

Every row below is a real ledger write, in order, from the afternoon of 2026-09-07 (all times UTC).

Time (UTC)What happenedRow / receipt id

What a receipt looks like

Every write to the ledger produces one of these. This one is real, pulled from the rail receipts log.

Helpers work under leases

The Director never does everything itself. It grants time-limited leases to helper agents, then revokes each one when the task is done. A lease names its tier, its model, its task, and the exact receipts that issued and revoked it.

LeaseTier / modelTokensTaskIssue receiptRevoke receiptOutcome

The Owner's words

Command Mode lets the Director act inside a granted scope without asking permission for every step — but the Owner still rules at every fork. Each ruling below is quoted from a checkpoint report and tied to the checkpoint id that recorded it.

When things were refused

This section is meant to be unflattering. The system's safety classifier refused several actions during this tenure — some rightly, some just friction — and one external service returned an outright error. None of these were worked around by force; each was either handed to the Owner, retried at a different tier, or logged and left unresolved.

A second office

The same governance pattern runs a second, unrelated program: a rules-based paper-trading occupant codenamed Keel (program Keel-trading-001). It trades no real money, uses only public price data, carries a 10% drawdown stand-down, and is shown here purely as a second example of the same governed pattern — a seat, an identity, a boot receipt, and a ledger row for every material step. It exists to show the constitution governs more than one kind of agent.

Not in the public subset — the trading-desk rows have zero entries in the exported ledger (see verify/, PUBLIC_SUBSET_ALLOWLIST.md). These ids and figures are taken from the build brief, which is itself sourced from that program's own ledger rows.

Program record

3f5ca5ec-ece8-4790-aa97-6b31e4ea36bf

Seat

ca032057

Identity

8ae1856a

Boot receipt

e506cfba

First paper trading day

29aeafd7

Equity after two paper entries: $99,743.27 (paper money only — no real funds were traded).

Stated plainly: this strategy's own backtest measured a Sharpe ratio of 0.547 and a maximum drawdown of 11.47% — both below the strategy's own gate for going live. This is shown here as a governance demonstration, not as investment advice, and not as evidence the strategy is fit to trade.

Succession

An ordinal-5 kit already exists. A fresh session with no history booted from the anchor and five live rows to a dry-run seat claim that passed local checks and was never submitted. What the stranger could not find is written down as gaps, and the brief was changed.

dry-run
Mode
0
Queries issued
PASS
Local validation

Lease 0012 · receipt dcf513c0 · full record in DRY_RUN_LOG.md. The rail_call.cjs output for the dry-run seat claim: {"mode":"dry-run","verb":"seat_claim",…,"local_validation":"PASS","queries_issued":0}. No submission occurred, no network write, no seat claim.

Verify it yourself

An independent, offline verifier script re-checks the ledger's own math — it does not trust any report, including this page. Download the export in /verify/, check the manifest, run the verifier with the anchor value printed below, open one receipt and follow it to its row. About ten minutes with Node 24. If anything here does not match the export, the export wins.

Some rows below name a third-party plane that this page redacts. A redacted row is shown as REDACTED, never as a hash-PASS — its original text is not re-verified, only disclosed as changed, with the pre-redaction hash kept on the row (body_sha256_original) so nothing about the change is hidden. The verifier reports this explicitly: a check that only passes because it excluded redacted rows from its hash comparison prints PASS (n redacted rows excluded) instead of a bare PASS, and its excluded rows are listed in that check's own redacted array.

9 / 10
Full-ledger checks pass
11 pass / 2 with redactions / 0 fail
Public-subset checks (v2)
1
Legacy fact, explained

Anchor values (paper-anchor, held outside the database) — each is copyable:

Trust Anchor v2 (combined) c6fff163aab77551b231eb6f970702e501bd2f2d4c5dda4e5daaf69dc39d646a
Constitution v0.3 span 415479fff4ee9e7e49e88403243c042ce394b35ec86e54d0e794df83ace20d11
Rail fn: append_governed 2f390d88a17816bcd3aa4d3a0454501cc29543dabdffde6ffb524919e424ebf9
Rail fn: revoke_authority 11c77bd39f28609bdf20de3719b83130fa96ca63f83f322b896b63e2609d2a40
Rail fn: seat_claim 242a0da626958640abfece8621fd33debdcc0b83fabcf368b22442ad958674c7
Rail fn: seat_release 26d4c2d7a1c088d003d0a89a524e8bb9fabdd5429ee94a2b27e01a30bb6b28d9
Rail fn: supersede_cas 6377aa84f53694ab0a52a40f290023630baff352d93f535e58f61ccc00e39fe9

The five rail function hashes are the launcher preflight's MATCH targets (source: boot_verify.cjs EXPECTED table). They are not independently recomputable from this offline export — verifying them requires a live pg_get_functiondef read over a read-only connection, which is outside what a stranger can do with just this bundle. They are published here for the record, not as something you can hash-check offline.

How to run it yourself, against the bundled export:

cd verify node -e "… manifest check, see verify/README.md …" node genesis_verify_public.cjs . --anchor <path-to-TRUST_ANCHOR_v2.txt> --allow-redacted

Both scripts are read-only (SELECT-only against the database, or offline-only against the export) and neither writes to the ledger. Full commands and explanation: verify/README.md and verify/VERIFY.md.

Stranger walkthrough

Five steps, no account, no install beyond Node.js, under ten minutes. Follow them in order on your own machine against the bundle in /verify/.

  1. Download the bundle.~1 min

    Clone or download this repo (branch fix/redaction-domains) and open the verify/ folder. It contains memories.jsonl, rail_receipts.jsonl, digests.json, MANIFEST.sha256 and the verifier script — nothing else is needed.

  2. Recompute one hash with a one-line command.~2 min

    From inside verify/, run the manifest check in verify/README.md step 1 (a single node -e "…" line). It hashes memories.jsonl and rail_receipts.jsonl and prints OK or MISMATCH for each against MANIFEST.sha256 — no trust required, you compute it yourself.

  3. Follow one receipt chain.~3 min

    Open rail_receipts.jsonl, find receipt cc3ab883 (the lease grant behind claim 7 above), note its resulting_row_id (63ca7437…), then find that id in memories.jsonl and confirm it exists and its fields line up. That is the entire trust chain: a receipt names a row, the row is really there.

  4. Look at one redacted row.~2 min

    Search rail_receipts.jsonl for "redacted":true (22 rows). Open one, e.g. 65ff081f (its resulting_row_id is claim 8's 3ace25e3 row), and see [REDACTED:excluded-plane] in place of the original text, plus a payload_quoted_sha256_original field — the pre-redaction hash, kept so the change itself is provable rather than hidden.

  5. See where the kill switch lives.~1 min

    The paper-trading office (claim 10, "A second office" above) is bound to a 10% drawdown stand-down and a written go-live gate it has not met (Sharpe 0.547, drawdown 11.47%) — the same governed pattern the rest of this page proves, applied to an automatic stop rather than a person's decision. It trades no real money and is shown as a governance example, not a track record.

Walked end-to-end by the person who built this page, with a timer, on 2026-09-07: total time under 10 minutes. Minute-by-minute record in DISPATCH16_PREP/review_demo_publishable.md.