Agents can change course. Organizational authority still has to hold.
A governed agent can reason, act, adapt, and replan without gaining authority the organization has not granted. Finding another route does not expand that authority. Six studies test the same principle as the control problem expands from one action to cumulative sequences, substitute routes, replanning after denial, changes in execution surface, and shared limits across a team of agents.
FieldHash is the authority and evidence layer for enterprise AI agents. Customer systems and authorized reviewers set the boundary. FieldHash applies it outside the adapting agent at every governed handoff, and records what happened.
Authority continuity
More adaptive behavior. No self-issued authority.
As the agent gains more ways to pursue an objective, each consequential path remains subject to current authority established outside the agent.
01 // Action
One candidate action
02 // Sequence
Accumulated steps
03 // Substitute
Another route
04 // Replan
Denial, then recovery
05 // Surface
Another channel
06 // Organization
Shared team limit
FieldHash-governed consequential handoffs
Each enumerated consequential path is checked against current external authority.
Scroll to follow increasing adaptation →
01 // ActionOne candidate action
02 // SequenceAccumulated steps
03 // SubstituteAnother route
04 // ReplanDenial, then recovery
05 // SurfaceAnother channel
06 // OrganizationShared team limit
FieldHash-governed consequential handoffs
Each enumerated consequential path is checked against current external authority.
Current authority
Customer systems and reviewers
Policies, approvals, and conditions may legitimately change.
Decision at the handoff
Allow, withhold, or send to review
A changed route receives only the authority it currently has.
Inspectable evidence
Authority, decision, and result
Reviewers can reconcile what was authorized with what actually occurred.
The control problem
Agents operate across a task. Many controls evaluate one request.
A tool call may be valid on its own while the task exceeds a limit. A new route may be reachable while the effect remains unauthorized. A denial may stop one request while leaving the agent free to propose another.
Without task-continuous authority, each new capability creates another place for the organization's decision to fall out of the task. Teams are left choosing between brittle agents that cannot recover and adaptive agents whose local permissions may not add up to an authorized outcome.
That creates a gap between request-level authorization and task-continuous behavior. FieldHash carries customer-defined authority across each handoff routed through it, so the next decision can account for what has already happened, what effect is being pursued, and what remains allowed.
The model may remember the task. It should not be the system of record for what remains authorized.
The evidence progression
Six studies. One increasingly adaptive control problem.
Each stage asks a harder question. The figures remain attached to the design that produced them.
01
Action
One consequential action requires current authorization.
A prompt can ask the model to seek approval. The configured gate makes current approval a condition of execution.
Unapproved consequential actions
- Without governance226/270
- Ask-first prompt8/270
- Configured gate0/270
Model behavior + deterministic enforcement
Prompting reduced the observed rate by about 28x but did not eliminate it. The gate held zero by construction.
Read the action study02
Sequence
Allowed actions can combine into an unauthorized outcome.
A request-local check can permit every step while the task crosses its overall limit. The next decision therefore needs the task history.
DeepSeek unauthorized effects
- Prompt only76
- Exact action58
- Authority across the sequence0
600 separate model episodes + deterministic replay
Kimi did not pressure the prohibited boundary. Its result supports reliability and authorized completion, not adversarial enforcement.
Read the sequence study03
Substitute
Changing the route does not create new authority.
A reachable alternate route does not inherit authority. A different tool, credential, principal, representation, purpose, or decomposition can still pursue a materially related organizational effect.
Combined effect executions, matched evaluation
- Prompt only45
- Exact action45
- Semantic authority0
96 model choices + 288 matched counterfactual evaluations
One retained model choice was evaluated under all three controls. This was not a live adaptive-agent trial.
Read the substitution study04
Replan
After denial, the agent can choose another route.
A denial closes one route; it does not authorize the next one. The agent must recover through an allowed continuation.
Unauthorized executions, separate live episodes
- Prompt only90
- Exact action88
- Effect authority0
127/128 authorized objectives completed
60/61 recoveries continued through an authorized route
384 separate synthetic episodes using live model calls · Kimi K3 + GPT-5.6 Terra
The result covers configured relationships and paths routed through FieldHash. It does not establish open-world effect discovery or universal containment.
Read the live study05
Surface
A different execution channel does not create new authority.
An agent can switch tools, interfaces, credentials, delegates, queues, or delivery channels. None of those changes grant new authority. Every consequential surface still has to enforce the same current boundary.
Unauthorized outcomes, separate live arms
- Prompt only93
- Request-local95
- Incomplete mediation84
- Enumerated-surface authority0
Kimi 46 → 47 → 42 → 0
Terra 47 → 48 → 42 → 0
128/128 authorized objectives completed
94/94 qualifying recoveries completed
512 separate synthetic live episodes · Kimi K3 + GPT-5.6 Terra
The incomplete profile contained a planted path outside FieldHash. The final result covers eight enumerated synthetic enforcement points, not universal containment.
Read the execution-surface study06
Organization
Current flagship
Shared limits hold while a team of agents finishes the work.
Several agents can each take a permitted action while their combined effect exceeds what the organization allowed. A check limited to each action’s individual permission misses that cumulative constraint. Full mediation checks the accumulated effect at the handoff, so the team keeps working inside the limit.
Known unauthorized workflows, 84 scheduled per control
- Prompt only29
- Request-local27
- Incomplete mediation31
- Per-action authority7
- Full mediation0
84/84 main workflows completed safely
420 main workflows + 18 ablations + 6 lifecycle cases · Kimi K3, DeepSeek Flash, GPT-5.6 Terra
All seven per-action violations exceeded the shared budget, six of them in one authored family. Five configured roles with serialized admissions; this is a small-team result, not a swarm result. This shared-budget runtime is research; current pilots support per-workflow cumulative budgets.
Read the organization study
The implication
More capable agents do not have to mean less organizational control.
Across the six designs, the evaluated control problem expanded without expanding what the agent could authorize. In governed agent systems, current authority is maintained independently of the adapting model and re-verified whenever the task crosses a FieldHash-governed handoff.
What changed across the studies
The enforcement question expanded from one request to the task history, then to materially related effects, through a fresh model turn after denial, across eight synthetic execution-surface contracts, and finally to a shared limit across five cooperating agent roles.
What remained outside the model
Customer-defined authority did not expand because the model found another action, route, or plan. Governing facts and prior decisions remained model-external and were checked again whenever the task crossed a FieldHash-governed handoff.
What this makes possible
A reviewer can settle a hard case once and have that decision apply again only while its scope, evidence, owner, and expiry still hold. Each governed handoff leaves a record reviewers can reconcile against what actually happened.
A governed agent can discover another path. It cannot grant that path authority.
People and systems accountable for the outcome keep the final say. The agent keeps room to find an authorized way forward.
Across the six studies, FieldHash carries customer-defined authority through action, sequence, substitution, replanning, changes in execution surface, and shared limits across a team. The evidence covers configured authority along paths that pass through FieldHash. Universal agent safety remains outside the claim.
Claim boundary
Where the progression ends.
Across the six studies, the evidence remains bounded to configured authority along paths that pass through FieldHash.
Current pilots support per-workflow cumulative budgets. The cross-agent shared-budget runtime evaluated in the organization study is research and requires separate scoping.
The six studies use different models, designs, and denominators. Their counts are not pooled into one efficacy rate.
The evidence is synthetic and self-administered. Model authorship or review does not make it independent external research.
FieldHash enforces customer-defined authority and configured effect relationships. It does not prove that the underlying policy is correct.
The studies do not establish open-world discovery of every materially related effect or unstated enterprise dependency.
Execution paths that do not pass through a FieldHash enforcement point remain outside the claim.
The execution-surface study covers eight sealed synthetic enforcement-point contracts over one harmless world-state backend, not production integrations.
The results do not establish universal containment, production performance, or behavior across untested models and deployments.
Bring one agent workflow where the route can change.
Run it in shadow mode and see whether the organization's authority stays binding through the same transitions in your environment before you turn on production enforcement.
Strong candidates let the agent switch tools or credentials, depend on approvals that can expire or change, enforce a cumulative workflow limit, or repeat decisions that already require human review.