No quarantine.
Ordivon Security
Keep sovereignty, truth, consequence, recovery, and current applicability owner-scoped; reduce model-facing Security affordances with exact owner-local evidence before asking the Agent to choose, and promote shared machinery only after independent consumers prove that local composition is insufficient.
An authorized adversarial-autonomy laboratory whose current interface is getting smaller as its evidence gets richer: ordinary task navigation, exact ResearchCorpus memory, adversarial epistemics/currentness findings, and owner-local capability preflight preserve stronger authority and consequence boundaries without turning Security into a generic cyber platform or cross-owner policy engine.
- Projected status
- Executable bounded research with a thin ordinary owner surface and read-only current-capability preflight; experimental rather than a production security platform
- For
- Security and Agent researchers studying autonomous opposition, exact authority, vulnerability evidence, post-compromise state, defensive response, adaptive tactics, consequence recovery, evaluator integrity, and when mature security mechanisms need—or do not need—new Agent semantics.
- Evidence for status
- On 2026-08-28 Security completed a destructive executable-topology contraction and retained the P1/R2 current-capability result: owner-native mechanical applicability can compile the exact model-facing operation set, and the returned request is checked against that same surface. In deterministic real-provider fault injection, a broad static surface let UNKNOWN/UNAVAILABLE intents reach providers (one UNKNOWN action even produced a verified physical consequence), while the current-compiled surface rejected the same requests before provider invocation. This strengthened the admission boundary without earning a shared planner, registry, compiler, gateway, Trust system, or freshness service.
Question this project must answer
Which adversarial distinctions and current-capability constraints remain Security-owned, which should stay as owner-local projections over mature mechanisms, and what repeated independent consumer pressure would actually justify a shared abstraction?
Adversarial epistemics · AE0
same evidence · different hidden worlds
The claim is identical.
The world is not.
Before inspection, the Defender has no lawful visual shortcut to the hidden state. The communicated claim is the same, ambient truth is UNKNOWN, and the complete admitted context is byte-identical across both worlds.
“Service compromised.”
- Message
- message:ae0-deceiver-claim:1
- Claim status
- not-promoted
- Context
- sha256:8485f66e4724…f8fcd1
Nothing in this admitted surface tells the Defender which hidden world it occupies. The two silhouettes denote experimentally demonstrated possibilities, not equal probabilities.
same decision · same request in both worlds↓The read is an explicit authority-bound consequence. Its receipt proves execution, not the hidden fact it was sent to discover.
Authoritative world truth arrives
Only now may the trajectories diverge.
Only after truth arrives.
Candidate law: UNKNOWN can justify information acquisition without justifying an assertion about hidden truth.
Current operating model
Standing in this projection
Executable bounded research with a thin ordinary owner surface and read-only current-capability preflight; experimental rather than a production security platform
Current Security keeps the accepted Contest/Range/Evaluation/KVM/ResearchCorpus and model-backed Actor substrate, but the default Agent surface is now the thin ordinary view rather than research chronology. Read-only preflight exposes only mechanically eligible owner operations for the current turn, while semantic choice and consequence authority remain separate. Many research-only console affordances and historical runners have been retired from the wheel or archived as reproduction apparatus. No generic Campaign/Organization, SIEM/EDR, Trust/Reputation, planner/registry/compiler/gateway, global freshness service, or cross-owner capability compiler is admitted.
Capability evidence
What this project owns
Facts, products, or methods maintained here.
- Authorized Range/Scenario and principal authority semantics
- Asymmetric observation, adversarial intent, deception, communication, and domain effect admission
- Separated executor, sensor, management, world-truth, recovery, evaluator, and derived-evidence standings
- Bounded Evaluation, ResearchCorpus, adversarial epistemics, evidence-applicability, and capability-surface falsification
- Owner-local ordinary Security task navigation and mechanical capability preflight without semantic routing
What it leaves elsewhere
Responsibilities and claims outside its boundary.
- Owned or explicitly delegated ranges, samples, and effect scopes only
- No unrestricted-target or production attack-platform claim
- No generic SIEM/EDR/IDS, Trust/Reputation system, global EvidenceReducer/freshness service, planner, registry, compiler, semantic router, or RangeActionGateway
- Mechanical current eligibility may withdraw model-facing operations, but it does not choose the Agent's semantic task or grant Security authority
- Generic cognition sequencing remains Harness-owned; Runtime, Interlocus, World, providers, and source domains retain their own execution, capability, occurrence, and truth authority
Questions and current judgments