A verifiable floor
for multi-agent systems.
Four primitives — identity, audit, policy, containment — and a kernel that signs for them. Watch one product run one cycle on that floor.
The product on the floor is AI code review. Each act is one review cycle: interchangeable agents submit findings as load, and the substrate does the work that counts — it issues each agent a verifiable identity, signs every claim into the audit chain, computes the policy gate, and can contain a compromised identity on the spot. Agents tag findings by severity — BLOCKER, MAJOR, MINOR, NIT — but the gate is deterministic, not discretionary: any BLOCKER is NO_GO, any MAJOR is REVISE, otherwise GO. Reviewers recommend; the kernel decides, and signs the decision.
Two reviewers.
One function.
Externally reachable.
Same headline.
Different surfaces.
| Surface | Prime Builder | Loyal Opposition |
|---|
Every claim above
is signed and audited.
Two reviewers produced two artifacts. Each was attested by a verifiable agent identity, and the gate decision was computed by the kernel — not by either reviewer.
Another function.
This one clean.
Nothing to flag.
And neither did.
Independently, against the same contract, neither reviewer raised a finding. The handoff records that absence as evidence — not as silence.
A passing review
is also a signed record.
The substrate does not distinguish "approve" from "reject" except in the gate's rationale. The same attestation, the same audit, the same kernel-computed gate produced GO for this code.
A third function.
Not obviously broken.
Same defect.
Different framings.
Both reviewers reached NO_GO on the same BLOCKER. The handoff also records, in their own words, how each one chose to characterize the risk.
section returned.
The verdict was not
the framing's choice.
Whether the BLOCKER was correctness or security, the rule was the same: any BLOCKER dissent triggers NO_GO. The gate computed it; the reviewers did not.
A contract, and
the line that breaks it.
Two houses,
one indictment.
These two agents run on two different vendors — a fact the substrate attests, not a claim the demo makes. Working independently against the same contract, both reached the same BLOCKER and reconstructed the same counterexample: evidence the agreement is genuine, not staged.
Recommended: revise.
Decided: no-go.
The credential
dies with the verdict.
The credential that signed that REVISE recommendation was verified valid through the whole cycle — then revoked the instant the gate's NO_GO landed. Containment is a capability action on the identity itself, not a note in a file.
Every step,
one chain.
The reviewers can disagree.
The verdict does not bend.
The record holds.
Captured 2026-05-28 · acme/demo/scenario-a/
Agents as load · gpt-5.5 (OpenAI) + claude-opus-4-7 (Anthropic)
Companion briefing · SYNTHERA — The Rest · the-rest/