Trust states and incident narratives¶
Phase 5 of the Authority Control Plane replaces the scalar trust score with a state machine per principal that moves only on deterministic signals or by a person, with every transition sealed, and gives every incident a narrative: the expected path, the observed path, what Xybern did, and where the proof is. Live Sessions gains a Design / Live graph.
The four states¶
| State | Meaning | Narrowing, through the objects that already exist |
|---|---|---|
| trusted | the normal state | none |
| observed | signals accumulated in the last hour | warrants issued for at most one hour; outbound actions (send, export, publish, anything with external reach) held for a person |
| restricted | more, or worse, signals | spend above SAR 1,000 held; delegation refused (no grants, no child warrants); authority changes refused; outbound and irreversible actions held; warrants issued with a budget of ten actions and SAR 1,000 |
| quarantined | a forged token, a critically different executed effect, or twelve refusals in an hour | active sessions terminated, active warrants revoked, an incident opened, reads only until a person restores it |
The wire decision keeps its four values; the state arrives on the response as trust_state (with trust_signals and trust_transition when the decision produced them), on the Authority Slice (principal.trust_state), in the lineage and the receipt (lineage.agent.trust_state), in telemetry, and on the passport (posture.trust_state, with the sealed transitions as trust_history).
Signals¶
Every decision produces signals from what it already recorded, never from a model:
| Signal | Weight | When |
|---|---|---|
| unexpected_capability | 1 | a family never seen for this agent in 30 days (after 20 events) |
| unexpected_resource | 1 | a resource class never seen for this agent (after 20 events) |
| unusual_hour | 1 | an hour with no history (after 30 events) |
| new_delegation | 1 | a grant less than a day old was used (counted once for a grant, not for each use) |
| new_region | 1.5 | a region never seen for this agent |
| high_value | 2 | spend above 100,000, or above ten times the agent's median |
| unusual_sequence | 2 | a sequence rule fired |
| violation | 1 | refused by a rule (after 20 events) |
| repeated_refusals | 2 | three or more refusals in ten minutes (after 20 events, once per ten minutes) |
| drift | 2.5 | the mission judged the trajectory drifting |
| forged_token | 12 | a warrant or an inbound stamp that does not verify |
| effect_mismatch | 6 | the attested effect differed from the approved one |
The score is the sum of the weights of the signals in the last hour: observed at 4, restricted at 8, quarantined at 12, or at once on a forged token, a critical effect mismatch, or twelve refusals in an hour. Refusals count only for an established agent (twenty events of history): a new agent being refused while it is configured is noise, not a change in behaviour. The machine never lowers a state on its own except through quiet time: 24 hours without a signal restores one step down (restricted to observed, observed to trusted). Quarantine is restored only by a person.
Every transition is a row in trust_transitions with the signals that caused it and a Vault entry (trust_transition), and re-issues the passport so the resolver shows the new posture.
A person moves the state¶
POST /v1/enforce/agents/<id>/trust with {state, reason} (approvals scope), or the Passports view (Restore to trusted). GET /v1/enforce/agents/<id>/trust returns the state, the score in the last hour, recent signals and the sealed history. SDK: client.trust(agent_id), client.set_trust(agent_id, "trusted", reason).
Incident narratives¶
Every incident answers, from what was sealed at the time: what was the expected path (the mission's outcomes, or the standing authority, the approved effect, the authorities held), what was the observed path (the session's steps up to the incident with the step that triggered it marked, the steps outside the design, the actual effect comparison), what Xybern did (the sealed remediation steps), and where the proof is (the receipt, the authority as of the decision, the Vault entries). Open any incident in the Incidents view, or call GET /v1/enforce/incidents/<id>/narrative. A one-paragraph sentence sums it up for a report.
Live Sessions: Design / Live¶
Every active session in the Live Sessions view opens a graph with a toggle. Design is what the authority and mission allow (the agent, its allowed outcomes and forbidden outcomes with their capabilities, or its reachable capabilities under standing authority). Live is the steps the session actually took, in order, with each decision's colour, and the steps that lay outside the design. GET /v1/enforce/sessions/<id>/graph returns both as nodes and edges.