Justin Kavalir · Zenodo (CERN European Organization for Nuclear Research) 2026 · 2026
DOI: 10.5281/zenodo.22796523
Counts differ because each database indexes a different set of publications. We treat OpenAlex as the canonical count; Google Scholar is not shown (no API, and crawling it violates its ToS).
This preliminary architecture note extends the Judgment Assurance framework to AI agents that act rather than advise. Its organizing distinction is between capability and authority: an agent may be technically capable of an action without holding institutional authority to take it. The envelope specifies what the institution has delegated, not what the system is able to do. The note describes an external, deterministic enforcement gate evaluated before execution; four dispositions (allow, notification, escalation, hard prohibition); the requirement that boundary classification is a design-time institutional judgment rather than a runtime decision by the agent; dual accountability across an agent owner and an envelope owner; a record tiered by verifiability, in which agent-generated rationale is separately labeled and carries the lowest evidentiary weight; and a monitoring function that obligates a recorded disposition to findings, with escalation rate read as a two-directional health metric. It also states its own limits. Evaluation is action-level rather than plan-level, concurrency across simultaneous agents is unresolved, cross-envelope interaction is sequenced as a second phase, the architecture can be claimed only where the institution controls the execution path, and the envelope defines authority without enforcing isolation between agents. The note is positioned as an overlay on existing AI governance work rather than a replacement for it, and maps to the Define, Record, Own, Guard structure of the underlying framework. It is preliminary and published for critique. For related work and ongoing updates, see judgmentassurance.com.
No comments yet — start the discussion below.