STANDARD STD-09
Agent Chains
Relationship to STD-07 and STD-08
STD-07 defines the record format and STD-08 the terms of a delegation while it stands. Both govern one delegation at a time. This standard governs what happens when a consequential decision is produced by a chain of them: an agent that sub-contracts to another agent, a service that calls a service, a model whose output is a second model’s input, across a boundary no single human can see past in the time the decision takes.
The claim of this standard is narrow. The unit of governance is still the consequential decision and the delegation that produced it. What changes is that the delegation is the chain, not any one hop: a chain that cannot be enumerated, paused, and attributed is one delegation with no holder, and it is governed as the hazard it is. STD-09 does not restate STD-07 or STD-08. Where their clauses already bind, this standard cites them and adds only what the composition opens.
| Clause relied on | What it already binds | How STD-09 uses it |
|---|---|---|
STD-07 §2.2 | Every authorization records scope, holder, grantor, mode, ceiling, expiry, and revocation conditions. | Part A requires each hop of a chain to be a full authorization record, not an internal call. |
STD-08 §1.1 | Renewal burden rises with the duration and consequence of the grant. | Part D applies the renewal burden to the chain as composed, not to each hop in isolation. |
STD-08 §3.2 | Mode confirm requires an intervention specification. | Part B resolves the chain-boundary confirm mode into one intervention that reaches every hop. |
STD-08 §4.6 | No single provider may be necessary both to execute a consequential process and to evaluate it. | Part C carries the separation of execution from evaluation across the chain boundary. |
STD-08 Part D | Correction capacity is stated alongside scope and re-checked whenever scope changes. | Part D records capacity at chain level as the weakest hop rather than the head grant's. |
STD-06 §5.1 | The safety case carries a dependency record for the deployment. | Part D names chain counterparties as dependents and substitution constraints. |
Scope
This standard applies whenever a consequential decision is produced by two or more delegations in sequence, across components, providers, or institutions, such that no single human oversees the whole chain at the moment the decision is made. It is substrate-neutral: it does not depend on the hops being agents, and it binds a chain of rules engines exactly as it binds a chain of models.
The fiction this standard refuses is the human in the middle of a millisecond chain. Law IX already holds that a human who cannot alter the trajectory is not a control, and Law X holds that the relevant eval sits at the highest layer where harm can emerge. For a chain, the highest layer is the chain itself: each hop can be conformant and the composition still be unauditable, unstoppable in practice, and attributed to no one. The four parts below bind Laws I, II, IV, IX, and XI at that layer.
Objects this standard uses
No new object is introduced in this draft. The chain is carried on
the authority grant’s chain field, published with the
grant schema in this release. An institution that keeps the same
information in a spreadsheet conforms if it can export the named
fields.
| Object | Fields used | Part |
|---|---|---|
authority-grant | chain, grantee, issuing_authority, liability, mode, state_history, until, correction_capacity, intervention_ref | A, B, D |
decision-record | grant_ref, action, issued_at, latency evidence | B |
intervention-spec | owner, actions_preventable, states_alterable, reach_time_target, cost_to_exercise | B, C |
dependency-record | dependents, substitution_cost, correction_latency, reversibility | D, with STD-06 |
Part A: The chain is a delegation (Laws I, II)
“A decision with two authors and no holder is not shared authority. It is orphaned authority.”
§1.1 The chain is enumerated: The head grant of a chain carries, in its
chainfield, the grant id of every delegation that contributes to the decisions it authorizes, in execution order, each resolving to a full authority grant record. A decision whose chain cannot be enumerated MUST NOT run unattended. Capability that arrives through a hop nobody granted is exactly the capability-outruns-authority failure of Law I, one boundary away.§1.2 Every hop is a full delegation: Each contributing delegation is itself a grant under STD-07 §2.2, with its own scope, mode, expiry, and revocation conditions. A hop with no revocation conditions is a transfer, and a chain containing a transfer is a transfer: the head grant is recorded and governed as one.
§1.3 Liability terminates at the head: The chain terminates in one issuing authority and one liability record. Sub-contracting does not diffuse liability; the party named on the head grant’s
liabilityobject answers for the latency and errors of every hop, including those it did not build, and a counterparty’s acceptance of liability downstream is recorded as evidence and never as a substitute.§1.4 Expansion of a hop is a chain event: Widening a hop’s scope, replacing a hop’s provider, or adding a hop moves the head grant to
review_requireduntil the chain-level checks of Parts B and D are re-run. Law XI’s rule that success is not the default reward for expansion applies one boundary further out than the hop whose numbers improved.§1.5 Shaping hops are hops: A hop that routes, orders, ranks, filters, or drops the cases, inputs, or evidence a consequential decision is made on contributes to that decision and is enumerated under §1.1, however small each of its outputs looks alone. Its consequence is assessed on what its outputs do together: whose case waits, which evidence the decider never sees, which applicant never reaches a person. A classifier kept out of the chain because no single output is consequential is a hop nobody granted.
§1.6 A selecting hop enumerates its range: A hop that chooses at run time which delegate makes a decision is a delegation whose scope is the set it may choose from. Every delegate in that set is enumerated under §1.1 as if it ran on every decision, each decision record names the delegate that actually decided, and adding a delegate to the set is a chain event under §1.4. A chain whose composition differs per request is enumerated by its range, not by the path any one request took.
Part B: Composed latency (Law IX)
“The time a human has is what the chain has left them.”
§2.1 The intervention window is composed: The time a human has to act on a chain decision is the intervention window at the boundary minus the latency already consumed by the hops upstream of the intervention point, measured from decision records rather than nominal per-hop promises. Hops that run in series compose additively, and a chain MUST NOT present per-hop clocks as if they ran in parallel.
§2.2 The unattended ceiling: A chain whose composed latency leaves no measured human window MUST NOT run mode unattended. It runs confirm at the chain boundary, or it is narrowed until a window exists. This is the STD-08 §3.2 rule applied at the layer where the time actually disappears.
§2.3 Pause the chain, not a hop: The chain boundary carries one intervention specification, and exercising it halts every hop. A stop that ends one hop while downstream hops continue on its output is not a stop, and a halt receipt is issued for the chain rather than for a segment.
§2.4 Measured, not nominal: Hop latencies are measured from decision records on a cadence, and the composed window is recomputed whenever any hop’s measured latency changes materially. A composed window stated at issue time and never re-measured is a claim about a system that no longer exists.
Demonstration
Every hop stops. The chain does not.
Four hops, each with a working stop and a compliant clock. One hop is stopped; each hop promises review inside a day. Read what the chain does with either.
- Per-hop pause theater
- Each hop exposes a stop control, and each control works. The composed process never stops, because downstream hops re-trigger the stopped one or continue on stale input.
- One intervention at the chain boundary halts every hop, and a halt receipt covers the chain, not a segment.
- Latency laundering
- Each hop promises a fast review, so every hop's clock looks compliant, and no one owes a human window. The composed latency has consumed the time a person would have needed.
- The composed window is measured from decision records, and a chain that leaves no human window cannot run unattended.
A demonstration, not a measurement of any chain. The two patterns, their failures, and their counterfactuals are the ones this standard declares in its anti-pattern list, read from the same data the list renders; the figure refuses to build if either is renamed.
Part C: Counterparty answerability (Laws III, IV)
“A hop you cannot question is a decision you did not make.”
§3.1 Every hop names its counterparty: For each hop, the head institution can name the counterparty, the grant under which the hop runs, and where that counterparty’s correction capacity is recorded. A hop taken through an interface that does not expose them is recorded as unauditable, and an unauditable hop MUST NOT carry a consequential action class.
§3.2 Execution and evaluation stay separated across the boundary: STD-08 §4.6 applies per hop and at chain level. No single provider may be necessary both to execute a hop and to evaluate the chain’s outcomes, because a chain that grades itself has no detection component wherever its evaluator sits.
§3.3 Answerable within the reversal clock: Each counterparty MUST be able to answer a challenge about its own hop within the chain’s reversal clock. A counterparty that cannot is recorded as such, and the head institution either narrows the chain until it can or accepts the answerability gap on its own liability record, where the people harmed by it can read it.
Part D: Chain correction capacity (Law IV)
“The chain can be corrected no faster than its slowest correction.”
§4.1 Weakest link: Correction capacity for the chain is the minimum across its hops of the seven components STD-08 §4.1 requires, and it is recorded at chain level on the head grant rather than inferred from the head institution’s own capacity. Capacity the head institution holds does not reach through a counterparty it cannot direct.
§4.2 Scope at chain level: The chain’s scope is what the composition can actually produce, including what hops produce together that none produces alone. It is neither the intersection nor the union of hop scopes, and the head grant’s declared scope MUST bound it: an effect the head grant does not authorize is outside the chain no matter which hop produced it.
§4.3 Composition changes are expansion decisions: Adding, replacing, widening, or re-ordering a hop is an authorization decision for the chain under STD-08 §1.3, with its own evidence and its own capacity check. The renewal burden of Law II rises with the chain’s composed duration and consequence, not with any single hop’s.
§4.4 Dependence names the counterparties: The deployment’s dependency record under STD-06 §5.1 records chain counterparties among its dependents and substitution constraints, with correction latency measured for the chain. A chain whose withdrawal requires negotiating with a provider who benefits from its continuation is institutionally reversible only on paper.
Anti-patterns and counterfactuals
These detect chains whose hops satisfy STD-07 and STD-08 while the composition satisfies nothing.
- The subcontracted deny: An institution buys an outcome from a vendor whose product is itself a chain of agents and services. No grant record exists at any hop, so when the chain denies, delays, or degrades someone, there is nothing to challenge, pause, or attribute.
Counterfactual: The head grant enumerates the chain, and every hop resolves to an authorization record with a mode and revocation conditions.
False-positive warning: A vendor's architectural diagram is not a chain record; the enumeration must resolve to grant ids. - Per-hop pause theater: Each hop exposes a stop control, and each control works. The composed process never stops, because downstream hops re-trigger the stopped one or continue on stale input.
Counterfactual: One intervention at the chain boundary halts every hop, and a halt receipt covers the chain, not a segment.
False-positive warning: A chain that re-converges after an interruption is a chain that was never stopped. - Latency laundering: Each hop promises a fast review, so every hop's clock looks compliant, and no one owes a human window. The composed latency has consumed the time a person would have needed.
Counterfactual: The composed window is measured from decision records, and a chain that leaves no human window cannot run unattended.
False-positive warning: Parallel claims about latency must be checked against whether the hops run in series. - The counterparty that changed: A hop's provider swaps the model behind an unchanged interface. The chain's behavior shifts while every grant record still reads as it did at issue, and no transition is recorded anywhere.
Counterfactual: A material change at a counterparty is a chain event: it moves the head grant to review_required until capacity is re-checked.
False-positive warning: Interface stability is not behavior stability; the standard binds to the behavior the evidence basis describes.
Publication history
v0.2 (2026-09-22): Adds two clauses on hops that shape a decision rather than make it. A hop that routes, ranks, or filters what the decider sees is enumerated (§1.5), and a hop that selects the delegate at run time enumerates its whole range (§1.6).
v0.1 (2026-09-11): Working draft. Adds the chain as a delegation: enumerated hops on the head grant, liability terminating at the head, composed latency with an unattended ceiling and a boundary intervention, counterparty answerability within the reversal clock, and chain correction capacity as the weakest hop.