How Digital Empathy becomes one agent — a world model that cannot lie, intelligence pressed into the seams, a genome that compounds — in five arcs starting from what is already alive.
Jump by type — Decisions: the eight locks · Contracts: judgment queue, receipt registry, work candidate · Gates: arc 1, arc 2, arc 3, arc 4, arc 5 · Repairs: watchdog · Questions: Q1–Q6
The company is being built as one agent. Its perception is a world model that cannot lie: every fact carries where it came from, how fresh it is, and how much to trust it — claims stay labeled as claims until a receipt promotes them. Its action is intelligence pressed into the seams where companies actually stall — and seams run three deep: seams of work (handoffs, blockage, unowned questions), seams of truth (the gap between what we believe and what is real — the false green lives here), and seams of time (the gap between what happens and what the institution learns). Its learning is a genome: the ratified core of rules and judgment that compounds as models improve and can grow new bodies — and no agent ever edits its own germline.
The humane boundary: people are not components of this agent — they are its principals. Humans supply the ends; the agent-company supplies means. Robert is the fitness function. Nothing grades itself.
Measured against main as of yesterday. The surprise: the organs mostly exist. What is missing is three connections (brain→seats, eve↔warp, Neo↔team) and one repair (a broken court). And one small organ — the call-log worker — already runs the complete loop in production: it senses calls and sales email, judges privacy per message, writes Salesforce on its own, leaves Slack receipts, gets audited daily by a non-author, and alarms if its auditor goes quiet. The elephant already has one living cell.
The pattern already exists three times — the daily audit (a scheduled Claude Code session), warp's seat economy, and the dispatcher that wakes Neo's private task. Arc 1 promotes it to standing law, and retires DailyHQ properly: threads are bodies; ledgers are state. A chat thread may hold a mind's working context, never the company's durable obligations.
Judgment-queue contract (Worker side): typed task in {taskClass, evidence refs, context refs, deadline, authority class} → typed verdict out {decision, basis, receipts, confidence}; lease + timeout + fail-closed-to-silence. The Neo request ledger already implements the lifecycle — generalize, don't reinvent.
Dispatcher, versioned: Phase 1 of the 08-21 plan unchanged — dispatcher + launchd definition move into the repo; the reused Telegram secret is replaced with a purpose-specific Neo control credential; install/start/stop/rollback are deterministic; a dead-man's switch (call-log pattern) alarms on heartbeat loss.
Neo Ops (the Claude mind): a persistent/scheduled headless Claude Code session woken by the dispatcher exactly as the Codex task is today, same silence-biased continuation contract, state read from ledgers never scrollback.
DailyHQ migration: (1) extract — standing instructions → versioned runbooks, open obligations → ask ledger, operating knowledge → repo docs/genome; (2) stand up Neo Ops; (3) one parallel week, Codex thread read-only, decisions diffed; (4) retire — thread archived, never deleted; the 08-21 plan's “Daily HQ” references re-point to ask ledger + Neo Ops.
Done when: a queued judgment task is answered by a seat-backed session with zero metered tokens on the judgment path; dispatcher survives restart with durable receipts; no external write while health is unsafe; DailyHQ retired with nothing operational referencing it. Rollback: re-point the dispatcher at the dormant Codex task (kept 30 days); the queue is engine-agnostic by construction.
Stage one is the verifier wedge — “@Neo check” on the already-live mention path, answering with receipts from the sources the world model already reads. Stage two is ambient, per the 08-21 plan's safety architecture with this conversation's amendments bound in. The wedge earns socially what no shadow program can buy: a team that has watched Neo be right, with receipts, before Neo ever speaks unsummoned.
Wedge: trigger = existing mention path (74 baseline assertions); investigator = seat-side (Arc 1's first production proof), reads receipt sources, answers with the receipt + link + tier-honest hedging (T2 reported soft, T0 as fact); reply = existing idempotent door + firewall, unchanged.
Receipt-source registry (new, versioned): each source Neo may check — the identity it reads as, freshness semantics, trust-tier mapping. Doubles as Arc 3's dispatch toolbelt. Wedge done when: 10 real checks receipted in 2 weeks; zero false receipts (a wrong receipt is zero-tolerance); 2+ teammates using it unprompted.
Ambient amendments (bind over the 08-21 plan): (1) taxonomy = the three receipt-backed classes; approval-boundary fires on agent-directed asks only. (2) budget ≤1 reply/channel/day in code + reply window T+10min–T+2h with silent cancel when a human answers. (3) identity first: live readback proving bot-only posting + a negative test that turns red if a user token can reach the ambient write path — before shadow (the on-disk manifest still describes an app sending as Robert). (4) social contract: team told before shadow in any real channel; tone = receipts never people, offer-to-recheck stance, concede when corrected; mute honored forever + mute-pattern. (5) validation right-sized: golden-24+ replay incl. wrong-correction / being-corrected / quote-loop cases with negative controls; adversarial suite aimed at the gate layer (lease races, dedupe-window replay, mode-flip mid-flight); shadow 7 days for rate/cost/crash only; canary 14+ days, ≥5 real interventions rated by the humans in the thread, ≤1 “should have stayed quiet”. (6) global daily spend/reply circuit breaker auto-degrades to observe-only. (7) detector output is untrusted input to the investigator — a promotion never escalates privilege by itself.
Prevalence hypothesis (written before shadow): authorized channels produce ≥3 genuine receipt-backed opportunities/week. Measured lower → the fallback form factor is a daily stuck-thread digest, decided at shadow-exit review. Rollback: layered per the 08-21 plan — replies off → observation off → kill switch → revision revert; every write re-checks its gate at write time.
This closes the eve↔warp seam. A world-model finding becomes a typed work candidate; warp builds and courts it; verdict and deploy receipt flow back as ground-truth facts. The trick that keeps it safe: Neo's leverage grows while Neo's authority doesn't — courts carry verification (reviewer never the author), the ruling library carries routine judgment, and everything novel batches to you.
Work-candidate schema: {finding, evidence refs, proposed work class, blast radius (Plato change brief), authority class, rollback plan} — produced by Neo Ops seat-side, stored in the request ledger.
Authority: routine classes (test-fix, known-failure-class patch, doc sync) dispatch under ratified rulings cited by name; novel/destructive/scope-changing batches to Robert; the Neo control plane's forbidden list binds unchanged. Custody: warp's existing doors (sealed room / sandbox lane); deploys only under existing deploy rules with proven rollback; court verdict + provider receipt land as world-model entries with ground provenance.
v1 scope & done: read-only investigations + builds landing on courted branches; the first ten loops end at “PR ready + court verdict, Robert taps merge.” Done when one real Slack-sensed failure flows detection → candidate → build → court → tapped merge → deploy → receipt back in the world model → Neo closes the thread. Ten clean loops graduate the first routine class into the ruling library.
The honesty watchdog has never passed — four straight scheduled runs died on a freshness gate an unattended job structurally cannot satisfy. You said you have no standing preference, so this arc proposes three fixes and asks for your pick (Q1). Separately: a finished quote-entailment verifier gets wired in or deleted, genome deposits get real receipts instead of placeholders, and the two Salesforce-write postures get named so nobody “unifies” them by accident.
Watchdog Option A — self-seeding runs: the weekly job generates its trap seed at run start (freshness measured from run start, not a human gesture); an independent seeder leg keeps the trap sealed from the subject. Unattended-satisfiable by construction; keeps synthetic trap coverage. Option B — attended monthly: simplest; cadence drops; reintroduces the depend-on-a-human failure the system exists to remove. Option C — production-derived audit (recommended): retire synthetic traps; weekly, a non-author session samples N real claims Neo made and recomputes each against ground truth. Audits reality instead of a rehearsal; no seed gate exists to fail. C+A is a valid combined pick.
Repairs 2–5: wire the quote-entailment gate into the court-brief path or tombstone it · genome deposits carry real receipt refs, and a deposit without one is queryably labeled a claim · nothing is represented as ground without a receipt (honest labeling at insert time — the world model represents, never governs) · document draft-queue-human-drain vs. call-log-autonomous as two named trust postures with their justifications.
Done when: the picked watchdog passes 4 consecutive scheduled runs; the entailment gate has a caller or a tombstone; a sampled week of genome deposits shows zero unlabeled claims; audit cadence is visible on the One-Surface.
One versioned home for the heritable core: constitution, working manual, ruling library, skills, taxonomies, tone contracts, capability maps. Ratification is the only merge gate, amendments get an adversarial read before landing, and deletion is a first-class gene edit — the genome must stay compressible. Southtown was the accidental prototype of growing a second body; this makes it a quarterly drill.
Home (Q6): a dedicated repo fronted by the existing genome ledger service is the candidate; courts run on changes. Cold-start drill (quarterly, scripted): fresh machine, genome only — measure what re-grows across named categories (harness up, bay materialized, courts run, world model cycles, a review surface ships); score is a percentage with named gaps.
Selection input beyond Robert: teammate feedback and client outcomes enter the germline as labeled evidence — guarding against overfit to one person's taste — while ratification authority stays with Robert. Done when: cold-start test #1 has a scored receipt; every standing rule can name its home; a sampled ratification shows the court-read happening.
Arcs 4 and 5 run as continuous threads; the table pins only their first receipts. Nothing in Phase III/IV starts on an unproven Phase I substrate — the wedge is deliberately both the first product and the substrate's proof.
Option A (self-seeding traps), B (attended monthly), or C (production-derived audit — recommended; C+A is a valid combo)? This is the one broken court in the body and the ruling is currently orphaned.
Export or paste the thread's standing instructions and state, or grant a read-through session. What in that thread must survive verbatim?
Run Neo Ops on your Max seat, or stand up a dedicated seat? A dedicated seat cleanly bounds concurrency and separates identity; it also costs money.
Which low-sensitivity channel follows #bot-test in the ambient canary, and what monthly model-cost ceiling applies to the ambient path? (The 08-21 plan's defaults otherwise stand: public/internal only, 30-day metadata retention, Robert-only mode changes.)
If shadow measures fewer than ~3 genuine opportunities a week, do you pre-approve the pivot to a daily stuck-thread digest, or does that come back for a fresh ruling?
Dedicated repo, or extend the existing genome ledger service? And any objection to teammate/client evidence entering the germline as labeled selection input?
Canonical source: docs/ai/design/agentic-os-five-arcs-2026-08-22.md · amends the 2026-08-21 ambient plan (safety plane retained; sequencing, taxonomy, validation, and substrate changed) · inventory measured against main 3ecefc86f, 2026-08-21.