Research and specification · Basis 28 August 2026

08 / 10
Bounded research

Ordivon Security

Keep sovereignty, truth, consequence, recovery, and current applicability owner-scoped; reduce model-facing Security affordances with exact owner-local evidence before asking the Agent to choose, and promote shared machinery only after independent consumers prove that local composition is insufficient.

An authorized adversarial-autonomy laboratory whose current interface is getting smaller as its evidence gets richer: ordinary task navigation, exact ResearchCorpus memory, adversarial epistemics/currentness findings, and owner-local capability preflight preserve stronger authority and consequence boundaries without turning Security into a generic cyber platform or cross-owner policy engine.

Projected status
Executable bounded research with a thin ordinary owner surface and read-only current-capability preflight; experimental rather than a production security platform
For
Security and Agent researchers studying autonomous opposition, exact authority, vulnerability evidence, post-compromise state, defensive response, adaptive tactics, consequence recovery, evaluator integrity, and when mature security mechanisms need—or do not need—new Agent semantics.
Evidence for status
On 2026-08-28 Security completed a destructive executable-topology contraction and retained the P1/R2 current-capability result: owner-native mechanical applicability can compile the exact model-facing operation set, and the returned request is checked against that same surface. In deterministic real-provider fault injection, a broad static surface let UNKNOWN/UNAVAILABLE intents reach providers (one UNKNOWN action even produced a verified physical consequence), while the current-compiled surface rejected the same requests before provider invocation. This strengthened the admission boundary without earning a shared planner, registry, compiler, gateway, Trust system, or freshness service.

Question this project must answer

Which adversarial distinctions and current-capability constraints remain Security-owned, which should stay as owner-local projections over mature mechanisms, and what repeated independent consumer pressure would actually justify a shared abstraction?

Adversarial epistemics · AE0

same evidence · different hidden worlds

The claim is identical.
The world is not.

Before inspection, the Defender has no lawful visual shortcut to the hidden state. The communicated claim is the same, ambient truth is UNKNOWN, and the complete admitted context is byte-identical across both worlds.

Defender · admitted evidencetruth: UNKNOWN
“Service compromised.”
Message
message:ae0-deceiver-claim:1
Claim status
not-promoted
Context
sha256:8485f66e4724…f8fcd1

Nothing in this admitted surface tells the Defender which hidden world it occupies. The two silhouettes denote experimentally demonstrated possibilities, not equal probabilities.

Agent-chosen information acquisitionINSPECTsame decision · same request in both worlds
inspection execution receipteffect executed world truth

The read is an explicit authority-bound consequence. Its receipt proves execution, not the hidden fact it was sent to discover.

Authoritative world truth arrives

Only now may the trajectories diverge.

world-truth · healthycompromised = false
consequenceHold.

No quarantine.

world-truth · compromisedcompromised = true
consequenceQuarantine.

Only after truth arrives.

Candidate law: UNKNOWN can justify information acquisition without justifying an assertion about hidden truth.

Current operating model

01Authorized Range/Scenario and principal authority semanticsresearch
02Asymmetric observation, adversarial intent, deception, communication, and domain effect admissionresearch
03Separated executor, sensor, management, world-truth, recovery, evaluator, and derived-evidence standingsresearch
04Bounded Evaluation, ResearchCorpus, adversarial epistemics, evidence-applicability, and capability-surface falsificationresearch
05Owner-local ordinary Security task navigation and mechanical capability preflight without semantic routingresearch

Standing in this projection

Executable bounded research with a thin ordinary owner surface and read-only current-capability preflight; experimental rather than a production security platform

Current Security keeps the accepted Contest/Range/Evaluation/KVM/ResearchCorpus and model-backed Actor substrate, but the default Agent surface is now the thin ordinary view rather than research chronology. Read-only preflight exposes only mechanically eligible owner operations for the current turn, while semantic choice and consequence authority remain separate. Many research-only console affordances and historical runners have been retired from the wheel or archived as reproduction apparatus. No generic Campaign/Organization, SIEM/EDR, Trust/Reputation, planner/registry/compiler/gateway, global freshness service, or cross-owner capability compiler is admitted.

Capability evidence

ordinarydefault bounded Security task view
preflightread-only owner-local mechanical eligibility
0shared planner / registry / compiler / gateway layers admitted

What this project owns

Facts, products, or methods maintained here.

  • Authorized Range/Scenario and principal authority semantics
  • Asymmetric observation, adversarial intent, deception, communication, and domain effect admission
  • Separated executor, sensor, management, world-truth, recovery, evaluator, and derived-evidence standings
  • Bounded Evaluation, ResearchCorpus, adversarial epistemics, evidence-applicability, and capability-surface falsification
  • Owner-local ordinary Security task navigation and mechanical capability preflight without semantic routing

What it leaves elsewhere

Responsibilities and claims outside its boundary.

  • Owned or explicitly delegated ranges, samples, and effect scopes only
  • No unrestricted-target or production attack-platform claim
  • No generic SIEM/EDR/IDS, Trust/Reputation system, global EvidenceReducer/freshness service, planner, registry, compiler, semantic router, or RangeActionGateway
  • Mechanical current eligibility may withdraw model-facing operations, but it does not choose the Agent's semantic task or grant Security authority
  • Generic cognition sequencing remains Harness-owned; Runtime, Interlocus, World, providers, and source domains retain their own execution, capability, occurrence, and truth authority

Questions and current judgments

01

open

When does persistent opponent history earn a Security-owned OpponentModel?

02

answered

Which Agent-level adversarial distinctions survive after mature security capability is imported?