Authorize.
Execute.
Prove.
A fail-closed commercial constitution for converting permitted institutional demand into collected cash, bounded delivery, independent proof, accountable acceptance and recurring GoalOS relationships.
Every outbound effect is pre-authorized by a short-lived signed Execution Grant, then reconciled against an operation-bound connector receipt.
Constitutional boundary
The autonomous lane executes MONTREAL.AI-side standard actions only.
Production status
The reference package deliberately separates software readiness from corporate authorization.
Activation requires exact signed artifacts, real connector credentials, professional review, SHADOW evidence, a bounded CANARY and an explicit expiring certificate.
Ceiling control architecture
One canonical action vocabulary, threshold authority, two-phase effects, signed evidence and durable reconciliation.
1 · Constitution
Action Registry · State Machine · Catalog · Policy hashes
2 · Authority
Threshold-signed Activation Certificate and case-specific Authority Envelope.
3 · Effect
Signed Execution Grant → connector execution → signed result receipt.
4 · Proof
Signed audit chain · Evidence Docket · independent verdict · acceptance · Chronicle.
Authorize → execute → reconcile
Authority separation
Canonical action registry
All runtime, policy, state-machine, UI and test vocabularies derive from these 56 unique events.
| ID | Event | From → To | Zone | Effect | Direction | Policy / human | Connector operation | Execution grant |
|---|
State-machine explorer
Choose a state to inspect only the actions permitted from that state plus global kill and escalation events.
Permitted next actions
Activation & trust
Inspect the TEST-ONLY threshold-signed certificate and verify its signatures and exact bundle hashes in this browser.
Activation payload
Verification result
Required production authorities
Founder authority
Constitution, parent boundary, activated offers, value ceilings and kill ownership.
Compliance authority
Communications basis, privacy, contracting, tax, jurisdiction and regulated-function boundaries.
Security authority
Trust registry, connectors, keys, evidence custody, incident response and revocation.
Two-phase external-effects laboratory
Inspect the five outbound commands requiring pre-effect grants and the five inbound connector events requiring authenticated result receipts.
Outbound commands
Inbound connector events
Closed offer catalog
Only activated standard offers may enter the autonomous lane. Strategic deployments and Maison formation remain human-gated.
Exact quote calculator
Minor-unit arithmetic; no caller-selected price.
Proof-to-recurring-value chain
Execution, review, customer acceptance, Chronicle and successor promotion are separate decisions.
Mission
Objective, authority, acceptance, budget, evidence and prohibited actions frozen.
Evidence
Complete provenance, failures, interventions, costs and claim boundaries.
Decisions
Independent verdict → customer ACCEPT / REPAIR / REJECT → Chronicle disposition.
Successor
Fresh Mission 2 must outperform under equal or stricter constraints before promotion.
Commercial progression
Threat, incident & kill architecture
Global and case kill events dominate the normal state machine and preserve evidence before remediation.
Global kill
- Founder revocation
- Critical security incident
- Material privacy breach
- Systemic unsupported representation
- Payment-provider compromise
- Terms, catalog, policy or registry hash mismatch
Case kill / pause
- Demand basis or authority failure
- Prohibited use case or data class
- Non-standard terms
- Payment dispute or customer misrepresentation
- Unauthorized action or receipt replay
- Execution-grant expiry, mismatch or lease conflict
Conformance & release evidence
The package validates architecture and reference behavior. Real production authorization still requires connector-specific and field evidence.
Formal / static gates
- Unique event vocabulary
- Hash integrity across registry, catalog and policy
- No nonterminal deadlocks
- Kill-switch dominance
- Acceptance before Chronicle
- Chronicle before successor test
- Authority Envelope before mission execution
- Pre-effect grant on every outbound command
Field-validation gate
- Historical replay in SHADOW
- Real inbound opportunities in SHADOW
- Bounded CANARY under value and volume limits
- Zero unauthorized external actions
- Payment and contract reconciliation
- Customer disputes and acceptance recorded
- Independent audit of event and grant ledgers
- Explicit expiring ACTIVE certificate
Export center
Download canonical machine artifacts directly from the local console.