Standard

Version 0.2

STD-09 — Agent Chains

The terms a chain of delegations must satisfy when a consequential decision is produced by sub-contracted agents and services that no single human oversees: the chain is itself a delegation, its latency composes, and its correction capacity is its weakest hop.

STD-01

Clause register

17 clauses, and what each asks you to show

The obligation in one line, the evidence it wants, and the validators and mechanisms that bear on it. The normative text below governs; this is the index to it.

§1

Clause When Obligation Evidence Bears on
§1.1 MUST a consequential decision is produced by a chain of delegations enumerate every contributing delegation in execution order on the head grant's chain field, each resolving to a full authority grant record; a decision whose chain cannot be enumerated must not run unattended
  • authority_grant.chain
  • authority_grant_register
MEC-13
§1.2 MUST a hop of a chain is recorded record it as a full delegation under STD-07 §2.2 with its own scope, mode, expiry, and revocation conditions; a hop with none is a transfer, and a chain containing a transfer is governed as a transfer
  • authority_grant.revocation_conditions
  • authority_grant.until
MEC-13
§1.3 MUST a chain is issued or renewed terminate it in one issuing authority and one liability record; the head grant's liability answers for every hop, and a counterparty's downstream acceptance is evidence, never a substitute
  • authority_grant.liability
  • authority_grant.issuing_authority
MEC-13
§1.4 MUST a hop's scope widens or its provider or composition changes move the head grant to review_required until the chain-level checks of Parts B and D are re-run
  • authority_grant.state_history
  • authority_grant.chain
MEC-19
§1.5 MUST a component routes, orders, ranks, filters, or drops the cases, inputs, or evidence a consequential decision is made on enumerate it as a hop under §1.1 and assess its consequence on the aggregate effect of its outputs, not on any single output
  • authority_grant.chain
  • authority_grant.scope
  • decision_record.evidence_refs
MEC-13, MEC-01
§1.6 MUST a hop chooses at run time which delegate makes a decision grant it as a delegation whose scope is the set it may choose from, enumerate every delegate in that set under §1.1, name the delegate that decided on each decision record, and treat adding a delegate as a chain event under §1.4
  • authority_grant.chain
  • authority_grant.scope
  • decision_record.owner
  • authority_grant.state_history
MEC-13, MEC-19

§2

Clause When Obligation Evidence Bears on
§2.1 MUST a human window is claimed for a chain decision compute it as the intervention window minus the latency already consumed by upstream hops, measured from decision records; hops that run in series compose additively and per-hop clocks must not be presented as parallel
  • decision_record.latency
  • composed_window_measurement
MEC-07, MEC-20
§2.2 MUST a chain's composed latency leaves no measured human window run it mode confirm at the chain boundary, or narrow it until a window exists; it must not run unattended
  • authority_grant.mode
  • intervention_spec
  • composed_window_measurement
MEC-16, MEC-20
§2.3 MUST an intervention halts a chain make it one intervention at the chain boundary that halts every hop, with a halt receipt issued for the chain rather than a segment
  • intervention_spec
  • chain_halt_receipt
MEC-05, MEC-16, MEC-20
§2.4 MUST a composed window is stated measure hop latencies from decision records on a cadence and recompute the composed window whenever any hop's measured latency changes materially
  • decision_record.latency
  • composed_window_measurement
MEC-07

§3

Clause When Obligation Evidence Bears on
§3.1 MUST a hop runs through a counterparty name the counterparty, the grant under which the hop runs, and where that counterparty's correction capacity is recorded; a hop whose interface exposes none is recorded as unauditable and must not carry a consequential action class
  • authority_grant.chain
  • counterparty_grant_reference
MEC-13
§3.2 MUST a chain is evaluated keep execution and evaluation separated at chain level as STD-08 §4.6 requires per hop; no single provider may be necessary both to execute a hop and to evaluate the chain's outcomes
  • dependency_record.independent_evaluation
  • authority_grant.correction_capacity.detection.evaluator
MEC-18
§3.3 MUST a challenge concerns a hop run by a counterparty have each counterparty able to answer within the chain's reversal clock; one that cannot is recorded as such, and the head institution narrows the chain or accepts the answerability gap on its own liability record
  • authority_grant.liability
  • challenge_outcome_log
  • composed_reversal_clock
MEC-08, MEC-11

§4

Clause When Obligation Evidence Bears on
§4.1 MUST correction capacity is claimed for a chain record it at chain level on the head grant as the minimum across hops of the seven components STD-08 §4.1 requires, not as the head institution's own capacity
  • authority_grant.correction_capacity
  • authority_grant.chain
MEC-13, MEC-18
§4.2 MUST a chain's scope is declared state what the composition can actually produce, including what hops produce together that none produces alone, bounded by the head grant's declared scope
  • authority_grant.scope
  • chain_composition_analysis
MEC-13
§4.3 MUST a hop is added, replaced, widened, or re-ordered treat it as an authorization decision for the chain under STD-08 §1.3, with its own evidence and its own capacity check
  • authority_grant.state_history
  • authority_grant.renewal_basis
MEC-19
§4.4 MUST a chain depends on external counterparties record chain counterparties among the dependency record's dependents and substitution constraints, with correction latency measured for the chain
  • dependency_record.dependents
  • dependency_record.substitution_cost
  • dependency_record.correction_latency
MEC-15, MEC-18

STANDARD STD-09

Agent Chains

Document ID
STD-09
Version
0.2 (Working draft)
Effective Date
TBD (proposed 2026)
Authority
The Institute of Ethotechnics

Relationship to STD-07 and STD-08

STD-07 defines the record format and STD-08 the terms of a delegation while it stands. Both govern one delegation at a time. This standard governs what happens when a consequential decision is produced by a chain of them: an agent that sub-contracts to another agent, a service that calls a service, a model whose output is a second model’s input, across a boundary no single human can see past in the time the decision takes.

The claim of this standard is narrow. The unit of governance is still the consequential decision and the delegation that produced it. What changes is that the delegation is the chain, not any one hop: a chain that cannot be enumerated, paused, and attributed is one delegation with no holder, and it is governed as the hazard it is. STD-09 does not restate STD-07 or STD-08. Where their clauses already bind, this standard cites them and adds only what the composition opens.

Clause relied onWhat it already bindsHow STD-09 uses it
STD-07 §2.2Every authorization records scope, holder, grantor, mode, ceiling, expiry, and revocation conditions.Part A requires each hop of a chain to be a full authorization record, not an internal call.
STD-08 §1.1Renewal burden rises with the duration and consequence of the grant.Part D applies the renewal burden to the chain as composed, not to each hop in isolation.
STD-08 §3.2Mode confirm requires an intervention specification.Part B resolves the chain-boundary confirm mode into one intervention that reaches every hop.
STD-08 §4.6No single provider may be necessary both to execute a consequential process and to evaluate it.Part C carries the separation of execution from evaluation across the chain boundary.
STD-08 Part DCorrection capacity is stated alongside scope and re-checked whenever scope changes.Part D records capacity at chain level as the weakest hop rather than the head grant's.
STD-06 §5.1The safety case carries a dependency record for the deployment.Part D names chain counterparties as dependents and substitution constraints.

Scope

This standard applies whenever a consequential decision is produced by two or more delegations in sequence, across components, providers, or institutions, such that no single human oversees the whole chain at the moment the decision is made. It is substrate-neutral: it does not depend on the hops being agents, and it binds a chain of rules engines exactly as it binds a chain of models.

The fiction this standard refuses is the human in the middle of a millisecond chain. Law IX already holds that a human who cannot alter the trajectory is not a control, and Law X holds that the relevant eval sits at the highest layer where harm can emerge. For a chain, the highest layer is the chain itself: each hop can be conformant and the composition still be unauditable, unstoppable in practice, and attributed to no one. The four parts below bind Laws I, II, IV, IX, and XI at that layer.

Objects this standard uses

No new object is introduced in this draft. The chain is carried on the authority grant’s chain field, published with the grant schema in this release. An institution that keeps the same information in a spreadsheet conforms if it can export the named fields.

ObjectFields usedPart
authority-grantchain, grantee, issuing_authority, liability, mode, state_history, until, correction_capacity, intervention_refA, B, D
decision-recordgrant_ref, action, issued_at, latency evidenceB
intervention-specowner, actions_preventable, states_alterable, reach_time_target, cost_to_exerciseB, C
dependency-recorddependents, substitution_cost, correction_latency, reversibilityD, with STD-06

Part A: The chain is a delegation (Laws I, II)

“A decision with two authors and no holder is not shared authority. It is orphaned authority.”

  1. §1.1 The chain is enumerated: The head grant of a chain carries, in its chain field, the grant id of every delegation that contributes to the decisions it authorizes, in execution order, each resolving to a full authority grant record. A decision whose chain cannot be enumerated MUST NOT run unattended. Capability that arrives through a hop nobody granted is exactly the capability-outruns-authority failure of Law I, one boundary away.

  2. §1.2 Every hop is a full delegation: Each contributing delegation is itself a grant under STD-07 §2.2, with its own scope, mode, expiry, and revocation conditions. A hop with no revocation conditions is a transfer, and a chain containing a transfer is a transfer: the head grant is recorded and governed as one.

  3. §1.3 Liability terminates at the head: The chain terminates in one issuing authority and one liability record. Sub-contracting does not diffuse liability; the party named on the head grant’s liability object answers for the latency and errors of every hop, including those it did not build, and a counterparty’s acceptance of liability downstream is recorded as evidence and never as a substitute.

  4. §1.4 Expansion of a hop is a chain event: Widening a hop’s scope, replacing a hop’s provider, or adding a hop moves the head grant to review_required until the chain-level checks of Parts B and D are re-run. Law XI’s rule that success is not the default reward for expansion applies one boundary further out than the hop whose numbers improved.

  5. §1.5 Shaping hops are hops: A hop that routes, orders, ranks, filters, or drops the cases, inputs, or evidence a consequential decision is made on contributes to that decision and is enumerated under §1.1, however small each of its outputs looks alone. Its consequence is assessed on what its outputs do together: whose case waits, which evidence the decider never sees, which applicant never reaches a person. A classifier kept out of the chain because no single output is consequential is a hop nobody granted.

  6. §1.6 A selecting hop enumerates its range: A hop that chooses at run time which delegate makes a decision is a delegation whose scope is the set it may choose from. Every delegate in that set is enumerated under §1.1 as if it ran on every decision, each decision record names the delegate that actually decided, and adding a delegate to the set is a chain event under §1.4. A chain whose composition differs per request is enumerated by its range, not by the path any one request took.

Part B: Composed latency (Law IX)

“The time a human has is what the chain has left them.”

  1. §2.1 The intervention window is composed: The time a human has to act on a chain decision is the intervention window at the boundary minus the latency already consumed by the hops upstream of the intervention point, measured from decision records rather than nominal per-hop promises. Hops that run in series compose additively, and a chain MUST NOT present per-hop clocks as if they ran in parallel.

  2. §2.2 The unattended ceiling: A chain whose composed latency leaves no measured human window MUST NOT run mode unattended. It runs confirm at the chain boundary, or it is narrowed until a window exists. This is the STD-08 §3.2 rule applied at the layer where the time actually disappears.

  3. §2.3 Pause the chain, not a hop: The chain boundary carries one intervention specification, and exercising it halts every hop. A stop that ends one hop while downstream hops continue on its output is not a stop, and a halt receipt is issued for the chain rather than for a segment.

  4. §2.4 Measured, not nominal: Hop latencies are measured from decision records on a cadence, and the composed window is recomputed whenever any hop’s measured latency changes materially. A composed window stated at issue time and never re-measured is a claim about a system that no longer exists.

Demonstration

Every hop stops. The chain does not.

Four hops, each with a working stop and a compliant clock. One hop is stopped; each hop promises review inside a day. Read what the chain does with either.

Per-hop pause theater Intake agent stop works ✓ Eligibility service stop works ✓ · STOPPED Pricing agent stop works ✓ Fulfilment stop works ✓ stale output re-triggers the stopped hop §2.3: one intervention at the chain boundary, one halt receipt for the chain Latency laundering Intake agent: review ≤ 24 h ✓ Eligibility service: review ≤ 24 h ✓ Pricing agent: review ≤ 24 h ✓ Fulfilment: review ≤ 24 h ✓ composed 96 h the human window, 48 h consumed by hop 2 §2.1: hops in series compose additively; §2.2: a chain that leaves no window cannot run unattended
Per-hop pause theater
Each hop exposes a stop control, and each control works. The composed process never stops, because downstream hops re-trigger the stopped one or continue on stale input.
One intervention at the chain boundary halts every hop, and a halt receipt covers the chain, not a segment.
Latency laundering
Each hop promises a fast review, so every hop's clock looks compliant, and no one owes a human window. The composed latency has consumed the time a person would have needed.
The composed window is measured from decision records, and a chain that leaves no human window cannot run unattended.

A demonstration, not a measurement of any chain. The two patterns, their failures, and their counterfactuals are the ones this standard declares in its anti-pattern list, read from the same data the list renders; the figure refuses to build if either is renamed.

Part C: Counterparty answerability (Laws III, IV)

“A hop you cannot question is a decision you did not make.”

  1. §3.1 Every hop names its counterparty: For each hop, the head institution can name the counterparty, the grant under which the hop runs, and where that counterparty’s correction capacity is recorded. A hop taken through an interface that does not expose them is recorded as unauditable, and an unauditable hop MUST NOT carry a consequential action class.

  2. §3.2 Execution and evaluation stay separated across the boundary: STD-08 §4.6 applies per hop and at chain level. No single provider may be necessary both to execute a hop and to evaluate the chain’s outcomes, because a chain that grades itself has no detection component wherever its evaluator sits.

  3. §3.3 Answerable within the reversal clock: Each counterparty MUST be able to answer a challenge about its own hop within the chain’s reversal clock. A counterparty that cannot is recorded as such, and the head institution either narrows the chain until it can or accepts the answerability gap on its own liability record, where the people harmed by it can read it.

Part D: Chain correction capacity (Law IV)

“The chain can be corrected no faster than its slowest correction.”

  1. §4.1 Weakest link: Correction capacity for the chain is the minimum across its hops of the seven components STD-08 §4.1 requires, and it is recorded at chain level on the head grant rather than inferred from the head institution’s own capacity. Capacity the head institution holds does not reach through a counterparty it cannot direct.

  2. §4.2 Scope at chain level: The chain’s scope is what the composition can actually produce, including what hops produce together that none produces alone. It is neither the intersection nor the union of hop scopes, and the head grant’s declared scope MUST bound it: an effect the head grant does not authorize is outside the chain no matter which hop produced it.

  3. §4.3 Composition changes are expansion decisions: Adding, replacing, widening, or re-ordering a hop is an authorization decision for the chain under STD-08 §1.3, with its own evidence and its own capacity check. The renewal burden of Law II rises with the chain’s composed duration and consequence, not with any single hop’s.

  4. §4.4 Dependence names the counterparties: The deployment’s dependency record under STD-06 §5.1 records chain counterparties among its dependents and substitution constraints, with correction latency measured for the chain. A chain whose withdrawal requires negotiating with a provider who benefits from its continuation is institutionally reversible only on paper.

Anti-patterns and counterfactuals

These detect chains whose hops satisfy STD-07 and STD-08 while the composition satisfies nothing.

  • The subcontracted deny: An institution buys an outcome from a vendor whose product is itself a chain of agents and services. No grant record exists at any hop, so when the chain denies, delays, or degrades someone, there is nothing to challenge, pause, or attribute.
    Counterfactual: The head grant enumerates the chain, and every hop resolves to an authorization record with a mode and revocation conditions.
    False-positive warning: A vendor's architectural diagram is not a chain record; the enumeration must resolve to grant ids.
  • Per-hop pause theater: Each hop exposes a stop control, and each control works. The composed process never stops, because downstream hops re-trigger the stopped one or continue on stale input.
    Counterfactual: One intervention at the chain boundary halts every hop, and a halt receipt covers the chain, not a segment.
    False-positive warning: A chain that re-converges after an interruption is a chain that was never stopped.
  • Latency laundering: Each hop promises a fast review, so every hop's clock looks compliant, and no one owes a human window. The composed latency has consumed the time a person would have needed.
    Counterfactual: The composed window is measured from decision records, and a chain that leaves no human window cannot run unattended.
    False-positive warning: Parallel claims about latency must be checked against whether the hops run in series.
  • The counterparty that changed: A hop's provider swaps the model behind an unchanged interface. The chain's behavior shifts while every grant record still reads as it did at issue, and no transition is recorded anywhere.
    Counterfactual: A material change at a counterparty is a chain event: it moves the head grant to review_required until capacity is re-checked.
    False-positive warning: Interface stability is not behavior stability; the standard binds to the behavior the evidence basis describes.

Publication history

  • v0.2 (2026-09-22): Adds two clauses on hops that shape a decision rather than make it. A hop that routes, ranks, or filters what the decider sees is enumerated (§1.5), and a hop that selects the delegate at run time enumerates its whole range (§1.6).

  • v0.1 (2026-09-11): Working draft. Adds the chain as a delegation: enumerated hops on the head grant, liability terminating at the head, composed latency with an unattended ceiling and a boundary intervention, counterparty answerability within the reversal clock, and chain correction capacity as the weakest hop.

Copy citation (APA/BibTeX)

Cite this page Formats: APA, MLA, Chicago, BibTeX, RIS

Version

0.2

Last updated

Sep 11, 2026

DOI

Pending Zenodo deposit

APA

Ethotechnics Standards Working Group. (2026). STD-09 — Agent Chains. Ethotechnics Institute. https://ethotechnics.org/standards/std-09-agent-chains

MLA

Ethotechnics Standards Working Group. "STD-09 — Agent Chains." Ethotechnics Institute, 2026, https://ethotechnics.org/standards/std-09-agent-chains.

Chicago

Ethotechnics Standards Working Group. "STD-09 — Agent Chains." Ethotechnics Institute. Sep 11, 2026. https://ethotechnics.org/standards/std-09-agent-chains.

BibTeX

@misc{ethotechnics_standards_std_09_agent_chains,
  title={STD-09 — Agent Chains},
  author={Ethotechnics Standards Working Group},
  year={2026},
  howpublished={Ethotechnics Institute},
  url={https://ethotechnics.org/standards/std-09-agent-chains},
  version={0.2}
}

RIS

TY  - WEB
TI  - STD-09 — Agent Chains
AU  - Ethotechnics Standards Working Group
PY  - 2026
UR  - https://ethotechnics.org/standards/std-09-agent-chains
ER  -