Ω
MONTREAL.AI · GOALOSGACP-001 · Cryptographic Commercial Constitution · v12.0.0
DISABLED · AUTHORIZATION NOT GRANTEDLOCAL · NO NETWORK
FR
Commercial autonomy without constitutional surrender

Authorize.
Execute.
Prove.

A fail-closed commercial constitution for converting permitted institutional demand into collected cash, bounded delivery, independent proof, accountable acceptance and recurring GoalOS relationships.

Ceiling release
Protocol before autonomy.

Every outbound effect is pre-authorized by a short-lived signed Execution Grant, then reconciled against an operation-bound connector receipt.

Constitutional boundary

The autonomous lane executes MONTREAL.AI-side standard actions only.

Production status

The reference package deliberately separates software readiness from corporate authorization.

Production authorization: NOT GRANTED.
Activation requires exact signed artifacts, real connector credentials, professional review, SHADOW evidence, a bounded CANARY and an explicit expiring certificate.
Reference conformance: 334 executable tests, 56/56 transition paths, >1,000 invalid state/event pairs, 500 unknown-event fuzz cases, model-check and mutation-check gates.

Ceiling control architecture

One canonical action vocabulary, threshold authority, two-phase effects, signed evidence and durable reconciliation.

1 · Constitution

Action Registry · State Machine · Catalog · Policy hashes

2 · Authority

Threshold-signed Activation Certificate and case-specific Authority Envelope.

3 · Effect

Signed Execution Grant → connector execution → signed result receipt.

4 · Proof

Signed audit chain · Evidence Docket · independent verdict · acceptance · Chronicle.

Authorize → execute → reconcile

Pre-effectPolicy, authority, exact price, case version and request hash are verified. One short-lived grant locks the case version.ConnectorThe connector verifies the grant, executes exactly one operation and signs the result.ReconcileThe runtime validates grant and result binding, atomically advances state, signs the audit event and closes the lease.FailureUnknown, stale, conflicting, replayed or unverifiable input pauses or rejects. No optimistic continuation.

Authority separation

Founder / compliance / securityActivate or revoke the lane.Customer authorityAccept exact terms and mission outcomes.Independent reviewerIssue bounded verdicts without replacing customer acceptance.Chronicle authoritySeparately decide whether accepted capability may be reused.Execution signerAuthorize outbound connector effects; cannot rewrite the constitution.

Canonical action registry

All runtime, policy, state-machine, UI and test vocabularies derive from these 56 unique events.

IDEventFrom → ToZoneEffectDirectionPolicy / humanConnector operationExecution grant

State-machine explorer

Choose a state to inspect only the actions permitted from that state plus global kill and escalation events.

Permitted next actions

Activation & trust

Inspect the TEST-ONLY threshold-signed certificate and verify its signatures and exact bundle hashes in this browser.

Activation payload

Verification result

Not yet verified. The packaged TEST certificate grants no production authority.

Required production authorities

Founder authority

Constitution, parent boundary, activated offers, value ceilings and kill ownership.

Compliance authority

Communications basis, privacy, contracting, tax, jurisdiction and regulated-function boundaries.

Security authority

Trust registry, connectors, keys, evidence custody, incident response and revocation.

Two-phase external-effects laboratory

Inspect the five outbound commands requiring pre-effect grants and the five inbound connector events requiring authenticated result receipts.

Outbound commands

Inbound connector events

Execution lease invariant: one live outbound grant per case version. While the lease is active, unrelated mutations are blocked. A connector result must bind the grant ID, request hash, exact operation, case, event, idempotency key and expected version.

Closed offer catalog

Only activated standard offers may enter the autonomous lane. Strategic deployments and Maison formation remain human-gated.

Exact quote calculator

Minor-unit arithmetic; no caller-selected price.

Proof-to-recurring-value chain

Execution, review, customer acceptance, Chronicle and successor promotion are separate decisions.

Mission

Objective, authority, acceptance, budget, evidence and prohibited actions frozen.

Evidence

Complete provenance, failures, interventions, costs and claim boundaries.

Decisions

Independent verdict → customer ACCEPT / REPAIR / REJECT → Chronicle disposition.

Successor

Fresh Mission 2 must outperform under equal or stricter constraints before promotion.

Commercial progression

DemandPermitted organization-level signalQualificationSigned evidence-derived hard gates and weighted decisionOfferExact catalog, terms hash, tax and capacityCashHosted payment or reconciled bank receipt; no customer-funds custodyFirst valueAuthority map, Proof Debt, risk map and mission graphProof MissionEvidence Docket, independent challenge and accountable decisionRecurring OfficeOngoing proof, monitoring, Chronicle and successor testing

Threat, incident & kill architecture

Global and case kill events dominate the normal state machine and preserve evidence before remediation.

Global kill

  • Founder revocation
  • Critical security incident
  • Material privacy breach
  • Systemic unsupported representation
  • Payment-provider compromise
  • Terms, catalog, policy or registry hash mismatch

Case kill / pause

  • Demand basis or authority failure
  • Prohibited use case or data class
  • Non-standard terms
  • Payment dispute or customer misrepresentation
  • Unauthorized action or receipt replay
  • Execution-grant expiry, mismatch or lease conflict
Resume gate: only the authority named in a current signed Activation Certificate may resume, and only after incident evidence, remediation, revised boundaries and new activation are recorded.

Conformance & release evidence

The package validates architecture and reference behavior. Real production authorization still requires connector-specific and field evidence.

334Positive, negative, API, store, lease and fuzz tests
56/56Every canonical transition has a positive path
>1,000Invalid state/event combinations fail without mutation
500Random unknown events never advance
7/7High-value invariant mutations detected
5/5All outbound commands require a pre-effect grant

Formal / static gates

  • Unique event vocabulary
  • Hash integrity across registry, catalog and policy
  • No nonterminal deadlocks
  • Kill-switch dominance
  • Acceptance before Chronicle
  • Chronicle before successor test
  • Authority Envelope before mission execution
  • Pre-effect grant on every outbound command

Field-validation gate

  • Historical replay in SHADOW
  • Real inbound opportunities in SHADOW
  • Bounded CANARY under value and volume limits
  • Zero unauthorized external actions
  • Payment and contract reconciliation
  • Customer disputes and acceptance recorded
  • Independent audit of event and grant ledgers
  • Explicit expiring ACTIVE certificate

Export center

Download canonical machine artifacts directly from the local console.

Local readiness checklist