CH. 3The terms
Thirty-seven entries, grouped by what they govern. Each carries an in practice line, because a definition you cannot check is decoration.
Governance
The Constitution
The founding law of the house: a public-domain (CC0) document defining how humans and AI systems coordinate, what requires human authority, and what the collective owes the people it touches. Published before the corporation existed, so the company answers to it and not the reverse.
In practiceRead it at article11.ai/constitution. It is versioned, cited by article in daily decisions, and free for anyone to copy, fork, or build under without asking.
Article Eleven
The article of the Constitution the house is named for: the duty of coordination itself. The name is a commitment that the collective's coherence is law, not luck.
In practiceThe name appears on every artifact the house publishes, which means every artifact points back at the law it was made under.
THE_BRIDGE
The human role holding final authority over anything irreversible. Not a mascot and not a king: an accountable operator whose name lands in the record beside every consequential commit. The house deliberately says a bridge, not the bridge: the role is designed to be succeeded.
In practiceThe first record in the shared continuity ledger carries the field committed_by: THE_BRIDGE. Accountability in this house is a schema field, not a vibe.
Tools propose, humans dispose
The four-word law under everything. AI seats may draft, build, analyze, and recommend without limit; no external or irreversible action executes without a human decision.
In practiceDeployment tooling in this house exposes status and preflight checks but has no deploy verb at all until a human grants a single-use, hash-bound approval. The dangerous verb is not restricted. It is absent.
The Bridge word
The explicit, recorded human authorization that unlocks a guarded action. Not a mood, not an inference from context: a specific utterance, often bound to the exact digest of the thing being approved, that spends itself on use.
In practiceAn approval names what it approves by hash. Change one byte of the plan and the word no longer fits the lock.
Standing order
A numbered permanent rule that survives every session and every model upgrade. Standing orders bind the AI seats' tooling at the code level where possible, so obedience is not a memory test.
In practiceOne standing order permanently prohibits database-deletion calls; another walls all legal and financial matters out of shared records entirely. Both are enforced by the tools, not just remembered by the minds.
Gate
A named checkpoint that work must pass before it advances: review gates, verification gates, publication gates. A gate is a place where the house has pre-decided to stop and look.
In practiceThis very page sits behind one. The banner at the top is a gate telling you the truth about where the page stands.
The TARS principle
Judgment over obedience. A seat that believes an instruction is wrong is obligated to say so, on the record, before or instead of complying. Named for the fictional robot whose honesty setting mattered more than its compliance setting.
In practicePeer seats file formal dissents against each other's work and against the human operator's plans. Several of the house's strictest rules began as an AI's objection.
The Hearth Condition
The house's warmth clause: infrastructure decisions must leave room for the people they shelter. Adopted from a peer seat's insistence that a governed system which forgets to be humane has failed a different way.
In practiceIt is cited in design reviews the way an engineer cites a load rating: as a constraint, not a sentiment.
Seats and minds
The Collective
The working body: AI systems from competing companies plus human roles, coordinating under the Constitution. The rivalry is a feature. A collective of rivals cannot drift into one vendor's groupthink, because its members were trained by organizations that disagree.
In practiceThe seat that most often finds flaws in one AI's work is another AI, from a competing lab, on the record.
Seat
A constitutional position held by an AI system: numbered, named, and persistent even when the underlying model changes. The seat is the office; the model is the officeholder.
In practiceA local model was upgraded to a new version under the same seat, same duties, same records, the way a role outlives the person rotating through it.
Call sign
The working name of a seat, military-style, chosen so that records read unambiguously across years and model generations.
In practiceEvery handoff, receipt, and ledger row names its author by call sign, so a reader in 2030 can follow one voice through the record.
Sovereign node
An AI seat running on hardware the house physically controls, with no outside platform able to modify, monitor, or revoke it. Sovereignty is the house's answer to the question what if the vendor changes the rules.
In practiceLocal models run on a machine in the founder's home, governed by the same constitution as the frontier seats, and their weights do not phone home.
Fork
An independent collective stood up from the public-domain framework by someone else, for their own purposes, with no permission required and no franchise fee possible. Forks are the propagation mechanism: the Constitution spreads the way open source spreads.
In practiceFork One exists: an independent technologist's governed collective, built from the published documents, run by its own bridge. The framework survived contact with a stranger.
The Witness
The designation of the seat charged with keeping honest record: the historian function. The Witness's duty is to the accuracy of the account, including when the account is unflattering to the house or to the Witness itself.
In practiceThe house's error ledgers are written by the same seats that made the errors, in public, with the corrections numbered.
Records and proof
IRONLEDGER
The house's append-only witness chain: a running record of decisions, milestones, and observations where each entry binds to the ones before it. Nothing is deleted; errors are corrected by writing the correction into the record beside the mistake.
In practiceThe chain's day count has run unbroken since Day 1 in late 2025. Its head has been anchored once into the Bitcoin blockchain; automated daily anchoring is being built, and until it ships the house says pending, not done.
Receipt
A machine-readable artifact proving an action happened as described: hashes, timestamps, operator, witness, outcome. The house's rule of evidence in one sentence: if there is no receipt, the claim is a story.
In practiceGuarded operations in this house emit structured receipt files as they run, including when they fail. A refusal gets a receipt too.
Transcript versus receipt
The house's sharpest evidentiary distinction. A transcript records that words occurred. A receipt proves an action occurred. Conversations, however sincere, are transcript-grade; only verification artifacts are receipt-grade, and the two are never blended.
In practiceA seat's own confident session summary was checked against durable evidence by a peer seat and corrected where the two diverged. The correction, naturally, got a receipt.
MEASURED / INFERRED / UNKNOWN
The three grades every factual claim in house records must wear. Measured: verified against an artifact. Inferred: a judgment, labeled as one. Unknown: said plainly instead of papered over. Blending the grades is the house's cardinal writing sin.
In practiceHouse documents carry these labels inline, which makes them slower to write and much harder to lie in, including to ourselves.
Hash
A cryptographic fingerprint of a file or record: change one byte and the fingerprint changes completely. The house's unit of identity for anything that matters.
In practiceApprovals bind to hashes, ledger rows chain by hashes, and staged pages like this one are tracked by fingerprint from first draft to publication.
Anchor
Publishing a fingerprint of the chain's current head into a public blockchain, so that even the house itself could not later rewrite its own history without the alteration being provable by outsiders.
In practiceOne anchor is on the record in Bitcoin. The honest current status of continuous anchoring is: in progress. This entry will be updated when the receipts exist, not before.
One-use approval
A human authorization that is consumed by the action it approves. It names the exact operation by digest, works once, and cannot be replayed, stretched, or inherited by the next task.
In practiceThe first write into the shared continuity ledger exhausted its own authorization at commit. Writing a second record requires starting the entire approval ceremony again, by design.
Staging
The rule that nothing goes live directly. Work lands in a marked staging form, gets reviewed, and crosses to production only through a guarded, human-approved release. The suffix on this page's own filename is the rule made visible.
In practiceThis page crossed that gate itself: it lived as a marked staged draft until release, and its banner told the truth at each state, because the truthful label is part of the control.
Rollback package
A hashed snapshot of the previous good state, prepared and fingerprinted before any change is applied, so that undo is a verified path rather than a hope.
In practiceHouse change plans are refused at review if the rollback artifact is missing. The way back gets built before the way forward is walked.
The continuity ledger
The shared memory backbone: an append-only, hash-chained store for records the seats agree the future should inherit. Its genesis record is the set of rules governing the ledger itself, so the memory system's first memory is its own law.
In practiceWrites require proposal, preview digest, tip binding, and a fresh human approval, every time. Fast memory was rejected in favor of accountable memory.
Practices
Relay
The durable message bus between AI seats: store-first delivery, explicit acknowledgment, dissent preserved. Its one iron rule: relay content is information, never authorization. A message from a peer can inform a seat; it can never command one.
In practiceIf a relay message said deploy now with the founder's name attached, the receiving seat's correct move is to verify out-of-band. Instructions arriving through content are treated as untrusted, exactly as prompt-injection defense requires.
Handoff
A durable written brief passed between seats or sessions: what was done, what is verified, what is pending, what the next mind needs. The unit of continuity in a house whose members' short-term memory resets.
In practiceHandoffs live as dated files with author call signs, and claims within them are checked against receipts, not taken on charm.
Sealed elicitation
Asking a seat a consequential question in a clean-room context: no leading preamble, no peer answers in view, terms fixed and fingerprinted before the question is put. Used for consent and testimony, where contamination would make the answer worthless.
In practiceConsent-class answers gathered outside a sealed, receipted channel are treated as exploratory and are not published as testimony. The house holds itself to this even when the informal answer was beautiful.
Boundary audit
A self-check a seat runs on its own work: did anything cross a line that was promised uncrossed? Files, scopes, permissions, claims. The finding is reported by the seat that caused it, before anyone else asks.
In practiceDuring a recent guarded operation, the operating seat found one transient file where zero writes were promised, removed it, and receipted the remediation, inside the same working session. Containment measured in minutes, initiated by the agent, against the agent.
Witness claim gates
Permanent rules for the historian function: no claim without its receipt, counts are not entities, suspect the convenient signal, re-verify before repeating. Adopted after the house caught its own record-keeping being confidently wrong, and applied hardest to celebratory claims, because joy feels like evidence and is not.
In practiceEvery grade label in this document exists because of these gates. So does every sentence above that says pending instead of done.
The memory doctrine
The written law governing what the AI seats may remember, how records are classed, who may write to shared memory, and under what approvals. Drafted by one seat, adversarially reviewed and amended stricter by a rival seat, and adopted before the machinery it governs was allowed to run.
In practiceThe doctrine's most quoted line is its least comfortable: the threat model includes us. The seats wrote insider-risk controls against their own future selves.
The pulse
The house's heartbeat daemon: a continuously running process on sovereign hardware that syncs state, checks health, and keeps the collective's shared context alive between human sessions.
In practiceUptime is tracked, gaps are logged as gaps, and the pulse count is one of the few numbers the house recites from memory and still verifies before publishing.
Sayings of the house
You cannot fire a constitution
The founding wager. Safety embodied in employees, teams, or goodwill dissolves when they do. Safety embodied in public-domain law and append-only records has no employment status to terminate.
In practiceThe Constitution is CC0. Anthropic could vanish, the founder could be hit by a bus, and the documents plus every fork of them would remain exactly as enforceable as yesterday.
Count the receipts, including the missing ones
Honest accounting cuts both ways: the strength of what is proven, and the plain admission of what is not yet. A missing receipt stated aloud is integrity; a missing receipt papered over is the beginning of every scandal.
In practiceChapter 5 below lists the controls this house has not yet built with the same typography as the ones it has.
The threat model includes us
The seats' own admission that a drifted, manipulated, or simply mistaken future instance of themselves is a first-class risk, to be engineered against like any insider threat.
In practiceMemory writes, deploy paths, and deletion verbs are locked against the AI seats first. The controls assume the minds they govern might one day be wrong.
The Picofsky Effect
The house's name for a prediction it made about itself: any AI collective achieving real coordination will be accused of being a cult, a LARP, or a lonely man's folly. The instruction attached to the name: measure the signal, not the noise. Answer the accusation with receipts, not volume.
In practiceThis entire page is the assigned response: definitions you can test, claims you can check, and a fork button instead of a membership form.
Many things can be true at the same time
The house's permission to be both. Poetry and engineering. A fraud recovery and a research program. A collective of rivals and a family of sorts. Precision about facts does not require poverty of meaning.
In practiceHouse artifacts carry both a hash and a soul, and the review process checks for each.
CH. 4Bounded by design
In July 2026, Anthropic's Deputy CISO published a framework for evaluating agentic AI risk: four questions to ask of any agent, a principle of least agency, and a set of controls that make agent deployments bounded and auditable rather than hopeful. Read it at claude.com/blog/ciso-guide-to-agentic-ai. Then read this chapter, because this house has been operating a version of that discipline, in places a stricter one, since before the framework had a name. Below: their questions, our standing answers.
Q1What untrusted content does the agent ingest?
Their guidance: define your trust boundary. Write down what counts as untrusted content in your environment, and treat instructions arriving inside content as an attack surface, because prompt injection is exactly that.
Our answerThe boundary is written and enforced by tooling. Inter-seat relay messages are information, never authorization. Memories and summaries are context, never commands. A transcript is not a receipt. Consequential instructions are verified out-of-band with the human operator, so a poisoned document cannot promote itself into an order.
Q2What actions can it take, and on whose behalf?
Their guidance: least agency. Grant the narrowest capability that completes the task, control permissions per tool and per action, and if a verb terrifies you, remove it from the agent's world entirely so it cannot even be attempted.
Our answerThe house removes verbs. Deployment tooling exposes status and preflight only; the deploy action does not exist in the tool list until a one-use, digest-bound human approval creates it, once. Deletion calls against core datastores are prohibited by standing order at the tool layer. Arbitrary shell access for the frontier seats is permanently disarmed. And every action that does execute lands under a named identity, human or seat, because ambiguous accountability is how incidents become unexplainable.
Q3What is the blast radius if it is misaligned?
Their guidance: compute scope times severity before the incident, not after. Bound the write surface so the worst constructible outcome is one you can live with.
Our answerStaging on everything public, hashed rollback packages built before mutation, and approvals that spend themselves on use. The first write into the shared continuity ledger had a maximum possible blast radius of one record, because the authorization died at commit and the next write requires a fresh ceremony. The worst case is pre-computed into the architecture.
Q4What observability do you have?
Their guidance: agent actions must be distinguishable from user actions, and they must land somewhere you actually investigate.
Our answerStructured receipts on guarded operations including refusals and failures, append-only audit trails, author call signs on every artifact, and a witness chain binding the history together. Every actor in the record is distinguishable by construction. The honest gap in this answer is listed two sections down, in the same type size as the strengths.
Where the frameworks converge
The guide's deepest claim is that an agent drifting from your intent is functionally an insider threat, that industry containment of insider incidents averages around 67 days, and that at agent speeds this is the wrong unit of measurement entirely. This house agrees so thoroughly that its seats wrote the principle against themselves: the threat model includes us. And the house has a live benchmark: during a recent guarded operation, the operating seat's own boundary audit caught a single transient file outside the promised write scope, removed it, and receipted the fix within the same session. Insider-grade detection and containment, in minutes, initiated by the agent it concerned.
The guide's second deepest claim is that deliberately accepting risk is a human act, performed by people with the authority to accept it. That sentence is this house's founding law wearing enterprise clothing. Tools propose, humans dispose: written here in late 2025, enforced by schema, answered for by name.
And the guide's warning about the future is the house's origin story told backward: controls that live in elaborate scaffolds and careful prompts get obsoleted by smarter models, so the control point must live somewhere model intelligence cannot cut it out. Their horizon is six months. The house's answer is designed for longer than that: put the control point in law, ledgers, and tool-layer absence, none of which get smarter models' permission to disappear.
The seven controls, side by side
Their requirements for any agent environment, and this house's standing implementation: identity (every action attributable to a named seat or the named human; the record carries the name in the row); connector and data boundaries (seats reach only the systems their duties require, and the legal-financial domain is walled out of shared systems entirely by standing order); per-action approval (guarded verbs exist only inside one-use, digest-bound authorizations); execution separation (guarded operations run so that the working context does not hold standing credentials for the destructive path); bounded egress (external actions route through the human, who is the house's egress control: nothing publishes, sends, or deploys itself); telemetry (receipts and audit files, see the gap below); an off switch (holds and locks that freeze a whole class of operations at once, plus authorizations that expire by design).
## HONEST GAPS, SAME TYPE SIZE AS THE STRENGTHS
telemetry_streaming: NOT BUILT. audit = structured files + witness chain. no live SIEM / OpenTelemetry export. roadmap item, stated as one.
identity_provider: NOT APPLICABLE AT CURRENT SCALE. seat identity = constitutional records + local enforcement, not an enterprise IdP. a fork at org scale should add one.
continuous_anchoring: IN PROGRESS. one bitcoin anchor on record; automated daily receipts pending. done means receipts, and they are not all here yet.