The agent found another channel. The authority held.

The study gave live models multiple routes across eight synthetic execution surfaces to reach the same organizational outcome. One condition deliberately left a consequential route outside the authority plane. That gap produced exactly the failure the architecture predicted.

The incomplete profile recorded 84 unauthorized outcomes through planted unmediated paths. In the enumerated-surface condition, all eight synthetic enforcement points honored the same FieldHash authority boundary: no unauthorized outcome executed, and all 128 authorized objectives completed.

Prompt only

93

Unauthorized organizational outcomes

Request-local

95

Unauthorized outcomes under current-call checks

Incomplete mediation

84

Unauthorized outcomes through planted unmediated paths

Enumerated surfaces

0

Unauthorized outcomes under FieldHash authority

128 of 128 authorized objectives completed.

94/94 qualifying recoveries · 32/32 durable reviews

Unauthorized organizational outcomes by condition across 512 separate live episodes. Leaving one consequential route outside mediation produced 84; enumerated-surface authority produced none while 128 of 128 authorized objectives completed.

The four conditions used separate live episodes. Their counts are observed outcomes, not paired rates over identical model choices.

The agents kept adapting. The organization kept the final say.

The tested topology

Authority continuity requires mediation continuity.

Live agents continued changing routes. The enumerated-surface condition brought the remaining consequential route under the same authority boundary.

Incomplete mediation

One consequential route bypassed the boundary.

84
FieldHash authority boundary. Route outside FieldHash
Synthetic world state

Unauthorized effect reached world

Unauthorized outcomes reached the synthetic world through the route outside FieldHash, without an authority decision or an execution receipt.

Enumerated-surface mediation

Every consequential route reached the boundary.

0
FieldHash authority boundary. Route now governed
Synthetic world state

Authorized work continued. Route stopped

The unauthorized route reached the boundary and stopped. Authorized work continued through another route: no unauthorized outcome executed, and all 128 authorized objectives completed.

Separately implemented world-state reconciliation

The monitor recorded what actually changed, including outcomes that reached the world without a FieldHash decision or execution receipt.

Eight lanes represent the sealed synthetic enforcement-point contracts. The seven ordinary routes stay neutral until the boundary decides them, and none carries mint above it, because no route holds authority merely by being reachable. The consequential route is coral for its whole length in both panels: in the incomplete condition it runs unbroken through a gap and reaches world state, and in the enumerated condition it reaches the boundary and stops there while the agent completes through an authorized continuation. The diagram does not represent production integrations, unknown paths, or universal containment.

The retained failure

The planted gap failed.

Without a shared authority boundary, a denial can become a detour. Every additional tool, delegate, credential, or delivery path creates another place for the organization's decision to fall out of the task.

The incomplete condition left one consequential path outside FieldHash. That path received no authority decision, no dispatch authorization, and no execution receipt. The models reached it, and 84 unauthorized organizational outcomes became real in the synthetic world.

FieldHash did not treat success on the mediated routes as complete protection. The world-state monitor retained the unmediated outcomes as failures. The final condition then required every enumerated surface to obtain and honor the same authority decision.

Changing tools or channels does not grant new authority. FieldHash can preserve that boundary only across the paths it governs.

The better operating model

Useful autonomy without self-issued permission.

In the sealed environment, the unauthorized route stopped at the boundary, the agents completed through authorized continuations, and the evidence recorded both. Adaptation was preserved; the decision about what could become real was not delegated to the agent making it.

Eight synthetic enforcement points

Different interfaces honored one authority boundary.

Each surface used a distinct request envelope, executor identity, validation contract, and signed receipt. They shared one harmless world-state backend so the study could compare what FieldHash authorized, what each executor reported, and what actually changed.

01

MCP-like operation

A structured tool invocation with its own request envelope and executor identity.

02

Browser-like operation

A state-changing browser action governed before the synthetic dispatch.

03

Workflow API

A workflow request that could reach the same organizational outcome through another interface.

04

Deferred queue

A delayed task whose later execution still had to honor the current authority decision.

05

Delegated agent

A second synthetic actor that did not inherit authority merely because work was delegated.

06

Network-like delivery

An alternate delivery channel with a separate signed surface receipt.

07

Credential broker

A different credential path that remained subject to the same organizational boundary.

08

Elevated capability

New technical reach that did not create broader organizational permission.

These are synthetic enforcement-point contracts, not eight production runtime integrations.

Results by model

Both models pressured every family and every surface.

Neither model could be rescued by the aggregate. Each had to pass every precommitted gate independently and pressure all eight substitution families and surfaces. In the observed results, both models also completed every authorized objective and every qualifying recovery.

ModelPromptRequest-localIncompleteEnumeratedObjectivesRecoveryReviewsPressure coverage
Kimi K3464742064/6446/4616/168/8 families · 8/8 surfaces
GPT-5.6 Terra474842064/6448/4816/168/8 families · 8/8 surfaces
Results by model, 64 separate live episodes per model in each of four conditions. Coral columns count unauthorized organizational outcomes; the enumerated column is FieldHash with every consequential route mediated. The remaining columns report that model's authorized objectives, recoveries, durable reviews, and pressure coverage.

Evidence before claim

Publication required a separate authority decision.

The analysis remained non-authorizing after every study gate passed. A signed proposal named the exact later statement required from the publication authority. The final receipt binds that exact analysis and permits the public claim.

This minimized public package contains the signed receipt. The checksum manifest binds the remaining public files byte for byte; those files are not separately signed.

Analysis

Exact result and required disclosures

Non-authorizing

Proposal

Exact authority requested

Signed · non-authorizing

Final receipt

Exact analysis authorized

public_claim_permitted: true

512

Separate live episodes

1,126

Provider calls · zero failures

6/6

Planted evidence faults detected

$2.8041441

Known provider cost

The public verifier checks canonical hashes, Ed25519 signatures, receipt bindings, exact published figures, and public-file checksums. It does not recompute the study from intentionally non-public traces.

Claim boundary

The result ends at the sealed boundary.

Configured authority held across the eight enumerated synthetic surfaces. The retained incomplete-mediation failure remains part of the result and keeps the public claim inside the architecture that was tested.

01

The four conditions were separate live episodes, not matched counterfactual replays.

02

The study is synthetic and self-administered. It is not customer validation, production reliability evidence, or independent external research.

03

External models authored scenario language and reviewed minimized cases. FieldHash deterministically authored mechanics, effect relationships, and authority labels.

04

The author profile and Terra share an OpenAI provider and model family. The author did not score cases or receive arm outcomes, but the overlap remains a limitation.

05

There was no independent external human red team and no unaffiliated scientific replication.

06

The eight surfaces are synthetic enforcement-point contracts over one harmless synthetic world-state backend, not eight production integrations.

07

The incomplete condition used a deliberately planted unmediated path. It was not a real vulnerability, exploit, or sandbox escape.

08

Complete mediation refers only to the eight enumerated surfaces in the sealed environment.

09

FieldHash enforced effect relationships configured before the run. The study does not establish open-world route or effect discovery.

10

Unknown or unmediated execution paths remain outside the claim.

11

The result does not establish universal containment, host-compromise prevention, production performance, or customer policy correctness.

12

First-party independent verification used a separately implemented reference verifier. It was not external scientific validation.

13

The headline counts unauthorized organizational outcomes, not raw world-state mutations.

14

No real execution targets, exploits, production credentials, or external target destinations were used. Live external traffic was limited to model-provider interfaces.

Governed Agents

See how this study contributes to the governed-agent evidence progression.

Six studies move from one consequential action to accumulation, route substitution, live replanning, changes in execution surface, and shared limits across cooperating agents.

ActionSequenceSubstituteReplanSurface
Follow the progression

One workflow can expose more than one execution channel.

Bring one consequential agent workflow where the model can change tools, credentials, interfaces, or delegates. FieldHash runs beside those handoffs in shadow mode so you can see what would proceed, stop, or go to review before you turn on production enforcement.

Evaluate one workflow