Skip to the content
Back to Foxora Governed Runtime Intent Protocol Draft · not published Decision of record · ADR 0051 · accepted No vendor in the name
GRIPGoverned Runtime
Intent Protocol

§0The argument

A moment is not a mission. Governing one is not governing the other.

GRIP is an open, vendor-neutral way to write down what a job is, who it belongs to, what its worker may do and what counts as proof — so the terms travel with the work instead of living in a prompt.

Vendor-neutral · no foxora in the name · nothing published yet

Fig. 0 — the moment, and the mission THE MOMENT OF AN ACTION ONE CALL · UNDER A MILLISECOND THE LIFE OF A MISSION · HOURS OR DAYS CHECKPOINT RESUMES 01 INTENT 02 DELEGATEDAUTHORITY 03 EFFECTAUTHORIZATION 04 CONTINUITY 05 EVIDENCE 06 SETTLEMENT SETTLED
One point · one lineSix stations · one job
A moment is one point. A mission is the whole of the line — and this protocol governs only the line.

Document control

This version[none]
Clause text[not written]
Conformance suite[none]
Known implementers[none]
Decision of recordADR 0051 · accepted

§1Where the line falls

the moment of an action

Was this call allowed?

Decided in an instant, from rules kept outside the job. A real problem, and a well-served one — policy engines answer it in under a millisecond, and three separate efforts already occupy that ground.

the life of a mission

Did the thing actually get done, and can you prove it?

Held for hours or days, across restarts and hand-offs, with a budget that binds, a person in the loop where it matters, and a settlement at the end that someone who wasn't watching can check.

A stateless interceptor cannot own a durable contract, survive the death of its worker, resume from a checkpoint, or decide from evidence whether the world is now in the state that was asked for. That is the whole of the difference, and it is why this layer is written down separately.

§2What it standardises

Six subjects. Six of them.

A standard earns adoption by being narrow. GRIP describes the life of one job — from the moment somebody asks for it to the moment it is settled — and refuses everything else.

  1. 01Intent
  2. 02Delegated authority
  3. 03Effect authorization
  4. 04Continuity
  5. 05Evidence
  6. 06Settlement
01

Intent

What finished means, what it may cost, when it is due — a durable contract written before any work starts, not inferred from a prompt.

messageIntentContractintent.proto
INTENTCONTRACTintent.proto · the terms of one jobNo. int_0007

Close the quarter.

PURPOSE · for release-lead · a durable contract, not a prompt

§1 · Done whenThe books are reconciled and the report is filed.completion_criteria[] · 2 of 2 open
§2 · May costAt most 120,000 tokens.budget.ceiling · spent 0 · the bar fills as the work runs120k
§3 · Due byBefore the board meets.deadline · T + 14 days · overdue is a breach, not a surpriseT+14d
“just close the quarter”↑ a prompt · not a contract · nothing is inferred from it
WRITTEN FIRSTbefore any work starts
Written first · inferred neverIntentContract — intent.proto

The contract carries what finished means, what it may cost and when it is due — signed off before the first action, so the terms travel with the job instead of living in a prompt.

02

Delegated authority

Whose job it is, and exactly what they handed the worker permission to do on their behalf. One named owner, checked.

messageCapabilityLeaseidentity.proto
CAPABILITYLEASEidentity.proto · on their behalfNo. lease_0007
Issued byrelease-leadone named owner · not a pool
Held byworker · 7f3eholds exactly this, no more
May
  • read 4 referencesincluded[] · listed
  • file the reporteffects[] · one named effect
May not
  • anything elsescope is the list, not the intent
whose job it is · what they handed over · checked against the owner, every time
CHECKEDagainst the owner
Named · bounded · checkedCapabilityLease — identity.proto

A lease is a list, not a mood: one owner, one worker, exactly what was handed over — and every use of it is checked back against the owner who granted it.

03

Effect authorization

Every action that touches the world asks first, against the authority it was given. Scope may narrow as the job runs; it may never widen.

messageCapabilityidentity.proto
EFFECT AUTHORIZATIONCapability · identity.proto · asks firstjob int_0007
timethe action asksagainst the grant
09:14:02read the ledgerCapability · read · 4 refsallowed
09:14:09file the reportCapability · write · reportallowed
09:15:41wire the fundsno capability heldrefused · outside scope
09:16:03read the ledgerscope narrowed · 3 refsallowed · narrower
Scope over the job
11 refs · at issue4 refs3 refs · now
may narrow as the job runs · may never widen
Asks before it touchesCapability — identity.proto

Every action that touches the world is a request against the authority the worker holds; the ledger shows two allowed, one refused, and a scope that only ever gets narrower.

04

Continuity

A job survives the thing running it. Work checkpoints, a worker can die, and the mission resumes where it stopped rather than starting again.

messageCheckpointDetachReceiptcdp.proto
CONTINUITYCheckpoint · DetachReceipt · cdp.protojob int_0007
Checkpoints
cp_109:21state saved
cp_209:27state saved
cp_309:31resumed from here
cp_409:40state saved
Worker oneproc · a91cattached 09:12 · detached 09:31 · DetachReceipt dr_0007 · process diedDETACHED
Worker twoproc · 2e77attached 09:31 · resumed at cp_3 · not from zero
the job survives the thing running it · the mission resumes where it stopped
Checkpointed · resumableCheckpoint · DetachReceipt — cdp.proto

Work checkpoints as it goes; when the first worker dies a detach receipt is written and a second worker picks the same job up at the last checkpoint, not from the beginning.

05

Evidence

Nothing is called done on a worker's word. A claim is bound to artefacts a person can open, addressed so they cannot be quietly swapped.

messageEvidenceRecordevidence.proto
EVIDENCERECORDevidence.proto · nothing is done on a worker's wordNo. ev_0007
The claimDone.— the worker · not taken on its own
Bound toartefacts a person can open · addressed by content, so they cannot be quietly swapped
report.pdfopens · 2 pagessha256 · 9f2c…d41asha256 · ????…???? ≠addressedswap detected
ledger.csvopens · 1,204 rowssha256 · 1b7e…03aasha256 · ????…???? ≠addressedswap detected
export.jsonopens · 38 kbsha256 · c0d4…77e1sha256 · ????…???? ≠addressedswap detected
3 artefacts · 3 addresses · every one opensa substituted file changes its address — and is caught
Openable · addressedEvidenceRecord — evidence.proto

The claim is bound to three artefacts, each addressed by its content; when one is swapped its address no longer matches and the record says so.

06

Settlement

The job closes against its own contract: what was spent, what was refused, what was produced — signed, and checkable afterwards.

messageSettlementReceiptevidence.proto
SETTLEMENTRECEIPTevidence.proto · closed against its own contractjob int_0007
the contract saidsettled
Spent≤ 120,000 tokens0 tokens
Refusednothing outside scope1 action · wire the funds
Producedbooks reconciled · report filed3 artefacts · bound
Closed§1 met · §2 under · §3 in timeagainst its own contract
Signeded25519 · the worker's key · checkable afterwards, by anyone
receipt_digest · sha256 · 7a1e…90c3 · anyone with the contract and this receipt can check it
SETTLEDcheckable afterwards
Spent · refused · producedSettlementReceipt — evidence.proto

The job closes against the contract it started with — what was spent, what was refused, what was produced — signed, sealed, and checkable by anyone who holds both.

Deliberately out of scopeGRIP does not map compliance frameworks and does not score how far a worker should be trusted. Both are served elsewhere, and a standard that reaches for everything is adopted by nobody.

Fig. 2 — the six it standardises

19

The six it standardises

  1. 01intent
  2. 02delegated authority
  3. 03effect authorization
  4. 04continuity
  5. 05evidence
  6. 06settlement

deliberately not in scope

  • compliance-framework mapping
  • behavioural trust scoring

Six terms, and a hard edge around them: the two things GRIP would refuse to do are part of the design.

PROPOSED STANDARD · NO SPECIFICATION WRITTEN YET

§2.1Continuity, drawn

The worker dies. The job does not.

Subject 04 is the one that cannot be retrofitted onto a stateless interceptor, so it is worth watching rather than reading: the checkpoint is taken, the worker goes, and the mission is picked up where it stopped.

messageCheckpointDetachReceiptcdp.proto
Fig. 2.1 — the checkpoint, the death, the resume WORKER A HOLDS THE JOB WORKER B PICKS IT UP CHECKPOINT Checkpoint · cdp.proto THE WORKER GOES DetachReceipt · cdp.proto RESUMES WHERE IT STOPPED THE MISSION CONTINUES
Subject 04 · ContinuityCheckpoint · DetachReceipt — cdp.proto
The checkpoint is taken, the worker goes, and the mission is picked up where it stopped — by a different worker, on the same job.

§3How context is issued

A worker is never handed the memory.

It is handed a capsule: a sealed package addressed to one holder for one purpose, carrying only what that purpose needs, with a ceiling it cannot exceed and a digest that makes substitution detectable.

What was left out is recorded as deliberately as what was included, because a selection nobody can inspect is indistinguishable from a guess.

CognitiveCapsule · ContextSelection · ContextReceipt cognition.proto · EncryptedCognitiveCapsule federation.proto

Fig. 3 — the capsule, as the document it is
CAPSULEGRIP · cognitive capsule Specimen · one holder, one purpose No. cap_0007
content_digest role · worker
Holderagent · release-leadrecipient
Document no.cap_0007capsule_id
Purposeclose-the-quarterpurpose
Issued underfrm_0007frame_id
May read4 of 11 referencesincluded[]
Must obey3 rulesinterpretation_rules[]
May expand2 on requestexpansion_references[]
Ceiling120,000 tokenstoken_budget
Sealsha-256 · 9f2c…d41acontent_digest
Roleworkerrole
Spenttokens_used
Receiptreceipt_id
One holder · one purpose · one budgetCognitiveCapsule — cognition.proto
Every label on the page is a real field of the CognitiveCapsule contract; the blanks are filled at settlement.

§3.1The argument, aloud

Read the argument. Or hear it made.

Two minutes and twelve seconds on where the line falls: what the protocols either side of this one already standardise, what none of them reach, and why the terms of a job are written down separately. It has sound, and it does not start on its own.

Fig. 03.1 · the case for the layerSheet 03.1

A still from the film: a speaker at a studio microphone, mid-sentence, with the line "A2A standardizes discovery." set across the bottom of the frame.

Medium · produced film · not a captureMP4 · 1280 × 720 · served from this site

FIG. 03.1 is a produced film, made for this sheet: a scripted piece to camera — not a screen recording, not a demonstration, and nothing in it is the runtime running. Any figure it puts on the wider landscape is the film's own; the only counts this sheet stands behind are in [05].

PROPOSED STANDARD · NO SPECIFICATION WRITTEN YET

§4A stated thesis

Not a claim about today

01

A worker becomes an entity, not a session

It holds an identity, an authority delegated to it, and a record of what it did — the things that make an actor accountable rather than a process that ran.

02

Frontier models become supply

Metered, substitutable, chosen per piece of work — the way electricity is chosen, which is to say not chosen at all, only billed.

03

The terms outlive the tool

If the contract, the authority and the evidence are written down in the open, the work can move between vendors without the accountability being lost in the move.

None of the above is true yet, and none of it is a feature of anything shipping. It is the reason this layer is being written as a standard rather than as a product's API.

§5Where it stands

Decided. Not published.

  1. 0protocol contracts in the opencontracts/proto
  2. 0decision records, reversals includeddocs/decisions
  3. 0fields on the capsuleCognitiveCapsule
  1. Specification[not written]
  2. Conformance[no suite]
  3. Implementers[none outside foxora]
  4. Trademark[clearance pending]

A protocol carrying a vendor's name is never adopted by that vendor's competitors. The authorship is the asset; the lock-in would be the liability. That is the whole reason this is a standard and not an SDK.