Barycenters Systems · the discipline

Authority is a human's.

At exactly one point. Everything else is authority_effect = 0.

The way SRE made reliability an engineering discipline, Authority Engineering makes consequence one. A system doesn't earn trust by being careful — it earns trust by being built so that no machine, however autonomous, can bind a consequence a human didn't.

A new discipline · coined and practiced at Barycenters
The defining thesis

The world doesn't get to choose “autonomous OR safe.” Every human must have a say. Layer 0 is how it gets both.

an actor proposesagent or human
/admit decidesauthority_effect = 0
a steward signsthe one point · a human
it executes — or is refusedand is traced forever
Only the cyan step carries authority — and it is the only one a human performs. Everything else decides, records, and proves; it cannot grant.
The tenets
01

Authority enters at one point, and it is a human's

Every module is authority_effect = 0 — a decision, a record, a proof. Consequence enters only where a named steward signs. One door, and a person holds the key.

pervasive across the runtime · a dead object until a steward signs it
02

A decision is not a grant

/admit decides admissibility; it never mints authority. Minting a name grants nothing — a minted capability is dead until a steward binds it, then expires, spends once, and is bound to one action.

least-authority invariant · user-minted API ≠ user-minted authority
03

No quorum of agents binds

An authority-bearing bind needs a quorum with at least one verified human — and no army of agents can satisfy it. A quorum of agents is not a check; they share weights and jailbreaks and fail in one direction.

human-in-quorum · 1000 agreeing agents → REFUSED
04

The machine verifies; only a human signs

The factory is autonomous, but it holds only verify-only keys — exactly what a customer holds. The private signing seed lives with no automation. Autonomy of work never becomes autonomy of authority.

factory-authority boundary · welded in CI
05

Every decision is provable

Each decision is written to a signed, hash-chained log with inclusion and consistency proofs. Anyone can verify a specific decision, and that the log only ever appended, in O(log n). Check, don't trust.

RFC-6962 transparency log · trust is arithmetic
06

Govern consequence without holding the data

Policy is content-addressed and private sources stay isolated inside their namespace. We decide whether an action is admissible without ever seeing what's inside it. Yours, always private.

private-source isolation · a refusal at the wall, not a promise
What falls out — the commercial unlocks

None of these is a feature we bolted on. Each is a consequence of the tenets above — you get it the moment authority is proven, not asserted. It is why Layer 0 is a market and not a checkbox: the architecture pays these out for free, wherever an action is wired through the one point.

A compromised agent is still a bounded agent

Prompt-inject it, jailbreak it, turn it fully hostile — it still cannot bind a consequence past the boundary a human set, because it never held authority. It can only propose. Everyone else answers rogue-agent risk by watching a thing that still holds the keys; here the keys were never handed over.

falls out of tenets 02 · 03 — a decision is not a grant
Compliance becomes exhaust, not a project

Every consequence is already a signed, hash-chained, independently-recomputable receipt. The audit trail a regulator asks for is not something you build — it is the exhaust of the runtime, and a third party can verify it without your logs, your dashboards, or your word.

falls out of tenet 05 — every decision is provable
Autonomy you can actually insure

A ceiling that is proven, not promised is a ceiling you can underwrite. “This agent cannot move more than X, cannot touch Y” stops being a policy PDF and becomes a checkable proof — which is what turns autonomous action at real scale from terrifying into bankable.

falls out of tenets 01 · 02 — one point, least authority
Govern any model, identically

Because /admit decides and never executes, the intelligence layer is swappable underneath it. Govern GPT, Claude, an open-weight model, or your own — the authority layer does not change. You are never locked to a model vendor to keep your guarantees.

falls out of tenet 04 — the machine verifies; only a human signs
Authority that crosses a trust boundary

Two parties who do not trust each other verify the same decision, because it recomputes from public inputs — not taken on a counterparty's word. That is what lets authority span organizations: agent-to-agent, marketplace, and money movement, with no trusted middleman holding the pen.

falls out of tenets 05 · 06 — provable, without holding the data
Spend-once — for a capability or a dollar

A minted admission spends exactly once, bound to one action. The property that stops a replayed capability is the property that stops a double-spent dollar — so /admit sits upstream of money movement on any rail, with no-double-spend as a proof rather than a lock you must trust.

falls out of tenet 02 — expires, spends once, bound to one action
Locked source, open proof
Why we can lock the source and still be verifiable

Provable is not the same as open-source.

Our source is private, and it stays that way. That takes nothing from you: you never had to read our code to trust us, because the trust is carried by signed receipts, recomputable decisions, and the transparency log — not by inspecting our internals. You verify the proofs, not the program. Authority Engineering is what lets both be true at once: the crown jewels stay locked, and every consequence stays checkable by anyone.

Even off the grid
🛰️

Authority Engineering holds at the edge — over Starlink, or off it.

Because the proof is math and not a server, admission holds where the cloud does not: a forward operating base, a research station, a vessel. The Starlink and local-runtime adapters carry /admit to the edge, so a consequence is governed and proven even when connectivity is a satellite pass away — and reconciles to the chain when it returns.

Edge & off-grid adapters · local AI governance

The machine proposes. The machine proves.
The human decides. Always at one point.