Barycenters Systems · the discipline
At exactly one point. Everything else is authority_effect = 0.
The way SRE made reliability an engineering discipline, Authority Engineering makes consequence one. A system doesn't earn trust by being careful — it earns trust by being built so that no machine, however autonomous, can bind a consequence a human didn't.
A new discipline · coined and practiced at BarycentersThe world doesn't get to choose “autonomous OR safe.” Every human must have a say. Layer 0 is how it gets both.
Every module is authority_effect = 0 — a decision, a record, a proof. Consequence enters only where a named steward signs. One door, and a person holds the key.
/admit decides admissibility; it never mints authority. Minting a name grants nothing — a minted capability is dead until a steward binds it, then expires, spends once, and is bound to one action.
An authority-bearing bind needs a quorum with at least one verified human — and no army of agents can satisfy it. A quorum of agents is not a check; they share weights and jailbreaks and fail in one direction.
The factory is autonomous, but it holds only verify-only keys — exactly what a customer holds. The private signing seed lives with no automation. Autonomy of work never becomes autonomy of authority.
Each decision is written to a signed, hash-chained log with inclusion and consistency proofs. Anyone can verify a specific decision, and that the log only ever appended, in O(log n). Check, don't trust.
Policy is content-addressed and private sources stay isolated inside their namespace. We decide whether an action is admissible without ever seeing what's inside it. Yours, always private.
None of these is a feature we bolted on. Each is a consequence of the tenets above — you get it the moment authority is proven, not asserted. It is why Layer 0 is a market and not a checkbox: the architecture pays these out for free, wherever an action is wired through the one point.
Prompt-inject it, jailbreak it, turn it fully hostile — it still cannot bind a consequence past the boundary a human set, because it never held authority. It can only propose. Everyone else answers rogue-agent risk by watching a thing that still holds the keys; here the keys were never handed over.
Every consequence is already a signed, hash-chained, independently-recomputable receipt. The audit trail a regulator asks for is not something you build — it is the exhaust of the runtime, and a third party can verify it without your logs, your dashboards, or your word.
A ceiling that is proven, not promised is a ceiling you can underwrite. “This agent cannot move more than X, cannot touch Y” stops being a policy PDF and becomes a checkable proof — which is what turns autonomous action at real scale from terrifying into bankable.
Because /admit decides and never executes, the intelligence layer is swappable underneath it. Govern GPT, Claude, an open-weight model, or your own — the authority layer does not change. You are never locked to a model vendor to keep your guarantees.
Two parties who do not trust each other verify the same decision, because it recomputes from public inputs — not taken on a counterparty's word. That is what lets authority span organizations: agent-to-agent, marketplace, and money movement, with no trusted middleman holding the pen.
A minted admission spends exactly once, bound to one action. The property that stops a replayed capability is the property that stops a double-spent dollar — so /admit sits upstream of money movement on any rail, with no-double-spend as a proof rather than a lock you must trust.
Our source is private, and it stays that way. That takes nothing from you: you never had to read our code to trust us, because the trust is carried by signed receipts, recomputable decisions, and the transparency log — not by inspecting our internals. You verify the proofs, not the program. Authority Engineering is what lets both be true at once: the crown jewels stay locked, and every consequence stays checkable by anyone.
Because the proof is math and not a server, admission holds where the cloud does not: a forward operating base, a research station, a vessel. The Starlink and local-runtime adapters carry /admit to the edge, so a consequence is governed and proven even when connectivity is a satellite pass away — and reconciles to the chain when it returns.
Edge & off-grid adapters · local AI governanceThe machine proposes. The machine proves.
The human decides. Always at one point.