Ownership boundaries for the lean RPI core
RPI owns the authorized outcome through implementation, checks, direct repairs
and fresh final judgment. Plan shapes missing intent and may revise an approach
falsified by evidence within unchanged accepted outcome/scope. Implement edits
and collects facts. Validate independently judges the exact subject and alone
authors semantic verdict.v2 when persistence is selected. Memory is optional;
its operation references own recall, mining and curation.
Native authority
BD or the caller's tracker owns work/status/dependencies/handoffs. Git and repository policy own content/history and delivery. Native runtimes and callers own aggregate budgets, work selection, queues, claims, stops and subsequent outcomes. A skill grants no extra Git, tracker, publishing or credential permission. Existing caller authorization remains usable; do not invent another approval step merely because a phase changed. Keep one authoritative work account, not a parallel AgentOps ledger.
The runtime derives exact intent/subject identity, complete changed paths,
receipts and observed context identities. Never invent a model/context identity
or transcribe a fictional runtime packet. New requested proof uses protected
external non-Git storage; preserve legacy .agents/ proof under owner policy.
Plans, dashboards and reviews count as subject completion only when requested.
Direct repair and help
Known failures get direct repair. Evidence that disproves an assumption permits approach revision under unchanged acceptance and scope. Acceptance or authority expansion needs caller approval; useful source/generated changes already covered by a scope class do not. Cheap discriminating checks precede expensive judgment. Reserve finishing capacity and use valid exact-input receipts when applicable.
Unknown cause, recurrence, no progress or wrong objective warrants causal examination. A genuine stall admits at most one bounded fresh helper per incident inside existing authority and bounds. Do not build a helper chain for known failures or rename an unresolved incident. An unhelpful helper ends the attempt. Cancellation, refusal or spent real limits skip help; retry counts alone are not spent time/quota. Compact native recovery state preserves evidence, not new budget.
Optional specialists and adapters
Anti-ceremony, premortem, council, research, factories and runtime adapters are optional. Risk deepens evidence inspection without mandatory specialist dispatch. No Recall or Learn toll applies to trivial work. A selected factory remains behind its own coordinator, doctor and supervisor doors; its reconciler creates and repairs sessions. Concurrent writers require authorized disjoint source and regeneration scope and isolation. Pass bounded task evidence, not the author's desired verdict. Do not start another runtime merely because it exists.
The optional run_once.py developer adapter retains its explicitly selected
fixed-dispatch and finite-round contract in bounded-adapter.md.
It does not restrict native approach revision or implement direct repair for you.
Fresh judgment
The author cannot issue binding PASS. Judge legs read; implementers fix. Default to a fresh author-distinct same-family reviewer. Cross-model review is opt-in; an explicitly required unavailable leg leaves NOT_PROVEN. No fixed ten-minute cap applies, and no invocation renews caller/native limits.
PASS needs exact subject continuity, complete changed-path coverage, unchanged
acceptance, distinct context IDs and attested freshness, nonempty checked scope,
evidence for every criterion and empty not_checked. Incomplete proof remains
NOT_PROVEN; failed acceptance or proven out-of-scope changes remain FAIL.
Necessary findings never become optional to get green. Judge disagreement stays
visible and never becomes PASS by preference or majority vote.
Validate returns judgment, not a repair or delivery instruction. RPI completes existing authorized work before reporting, within real bounds. Report the subject, strongest evidence and any remaining acceptance gaps; persist a machine artifact only for a declared consumer or caller request. A new subject requires new final judgment. Mutating checks run on a disposable copy or committed subject so they cannot overwrite the judged working tree.
Observed guardrails and limits
The July 2026 unlisted-regeneration incident supports scope as a class; it does not authorize unrelated files. The July mutating-check incident supports the quarantine; it does not require rerunning every expensive check. The planning spiral supports smallest useful action; it does not forbid revising a falsified approach. These rules protect actual work and may be revised by later evidence.