Current stageR12-R20 local foundations
Live development scope

What is in motion now

updated from the public state
  • R4.1-R10Protocol + conformanceGuarded / conforming
  • R12Worker boundaries + permission receiptsImplemented locally
  • R13A2A / ACP transport + adaptersImplemented locally
  • R14Model Atlas + usage ledgerImplemented locally
  • R15Control rooms + private projectionsImplemented locally
  • R16Library intake + progressive onboardingImplemented locally
  • R18Trusted devices + recoveryFoundation / gated
  • R19Authenticator + mobile approvalsFoundation / gated
  • R20Multi-authority queues + routingFoundation / gated
  • M5Hosted tenancy + external operationsNot enabled

Green means the local contract or conformance work is implemented. Yellow marks a foundation whose production boundary is still gated. Red means the capability is intentionally not enabled.

Protocol in motion

How Relay works

From a bounded question to a defensible decision—with evidence, review, and human authority kept visible.

Default evidence gate

Relay does not ask every participant to agree. It asks them to leave enough evidence for the next participant—and the final authority—to understand exactly what happened.

Four steps

From question to decision

  1. 01 Bound the task

    Declare one question, inputs, constraints, risks, and acceptance criteria.

  2. 02 Submit evidence

    Attach methods, commands, artifacts, failures, hashes, and context.

  3. 03 Review independently

    Reproduce where policy requires it and preserve material disagreement.

  4. 04 Record authority

    A named person accepts, remediates, rejects, or defers.

Interactive example Follow one high-risk claim through Relay Open trace
Task Does the change satisfy the safety policy?

High risk. Owner and acceptance criteria declared.

Evidence Two independent bundles

Commands, environments, artifacts, failures, and hashes preserved.

Disagreement A reviewer finds a boundary failure

The contradiction remains visible and causes remediation.

Authority A human accepts the remediated result

The original finding remains in the causal history.

Canonical records

Five record types carry the work.

Type One line
Task

One bounded question, owner, risk, acceptance criteria

Event

Append-only transition with sequence and previous hash

Evidence

Method, commands, env, artifacts, hashes, failures

Review

Findings, independence declaration, AI disclosure

Decision

Human gate outcome; not writable by remote model clients

independent
Declared review independence—not inferred from a different model brand
reproduction
A second evidence bundle that re-runs the claim under declared conditions
human authority
A named person accepts, remediates, rejects, or defers the gate
projection
A rebuildable view (console, Slack, Notion)—never alternate authority
schema validity
Structure and hashes check out; neither proves a claim is true
One protocol, many contexts

Change the evidence threshold, not the record.

Profiles raise or lower what must be shown before a named human may accept work. They do not invent new sources of truth, merge models into a vote, or let a dashboard rewrite history. Expand a profile for what it covers, what it demands, and what it deliberately refuses.

01Scientific research+

Bound a claim (one primary question), attach methods and environments, preserve failures and exclusions, require independent reproduction for high-risk claims, keep adversarial findings attached, and record named scientific authority for acceptance—not silent model consensus.

Typical evidence
Commands, code/data versions, artifact hashes, reproduction packets, reviewer independence notes
Who decides
Named human scientific authority for consequential gates; community peer review remains external
Boundary
Relay proves process integrity, not that a theory is true. Canon stays in the relevant scientific record.
Status: synthetic high-risk research gates are implemented (M3); real domain data remains disallowed.
02Government and public-sector review+

Keep policy, procurement, grant, service-change, and public-program reviews inspectable: declare the question, preserve source versions, record impact and risk analysis, and make exceptions visible before an accountable official decides.

Typical evidence
Policy versions, source documents, consultation notes, impact assessments, legal/ethics review, exception records
Who decides
Named public-sector owner or authorised official; statutory and democratic oversight remains external
Boundary
No autonomous eligibility, benefits, enforcement, legal, or civic decisions. Sensitive public records stay private or appropriately redacted.
Status: domain-neutral candidate profile; synthetic fixtures and explicit authority gates come first.
03Education and assessment+

Model rubric-based marking, moderation, appeals, and consistency checks. Relay can hold the rubric version, samples of evidence considered, reviewer notes, and the teacher’s final mark—while keeping student identity and private work out of public records.

Typical evidence
Rubric id/version, anonymised samples, moderation notes, appeal trail, AI disclosure
Who decides
Teacher or designated assessor; appeals path stays human
Boundary
Assistance only—never autonomous academic judgement, auto-grades as final marks, or real student PII in public fixtures.
Status: synthetic rubric, moderation, and appeal gates implemented; no real student data.
04Hiring assistance+

Compare candidates against declared criteria with visible evidence, consistency checks, and review trails. Relay is decision support for a named hiring authority—not an opaque ranking engine.

Typical evidence
Job criteria snapshot, scored dimensions with sources, disagreement notes, AI disclosure
Who decides
Named hiring manager / panel with legal and policy accountability
Boundary
Deferred until dedicated privacy, fairness, discrimination, explainability, and appeal gates exist. No silent automated hire/reject. No real candidate data in public fixtures.
Status: deferred profile—requires threat models before any real-world use.
05Incident investigation+

Build inspectable incident timelines: what was known when, which artifacts support each claim, competing explanations, remediation evidence, and the post-incident decision (accept residual risk, change process, reopen).

Typical evidence
Logs (redacted), configs, command transcripts, timeline events, alternate hypotheses, fix verification
Who decides
Incident commander or named ops authority; blameless process still requires named gate outcomes
Boundary
Public fixtures stay synthetic. Real incidents must not leak credentials, customer data, or raw secrets into Git/Pages.
Useful across engineering, safety, security, and operations.
06AI tooling and integration development+

Capture the bounded actions behind MCP servers, plugins, connectors, and AI clients: schemas, manifests, tool calls, process launches, configuration changes, failures, fixtures, and reproducibility evidence.

Typical evidence
Tool schemas, manifests, runtime versions, dependency receipts, redacted traces, test fixtures, exit codes, hashes, and configuration diffs
Who decides
Named developer, maintainer, or security reviewer; Relay never authorises a connector or publishes a release by itself
Boundary
No credentials, token stores, browser caches, node_modules, private transcripts, customer data, or broad home-directory scans in the public archive
Status: local template and Library modules available; live connector custody and hosted collaboration remain gated.
07Audit and due diligence+

Assemble declared evidence packs for compliance, grants, procurement, or policy review: what was checked, what matched its hash, what was missing, what exceptions were granted, and what residual risk a human accepted.

Typical evidence
Control list, artifact inventory, verification results, gap register, exception rationale, acceptance record
Who decides
Named auditor / accountable owner—software does not “pass the audit” alone
Boundary
Gaps and exceptions stay visible. A green dashboard is not a substitute for a decision record.
Applicable to compliance, grants, procurement, and policy review.
Trust boundary

Integrity is not truth.

Relay’s job is to make the path to a decision inspectable. A valid schema and a matching hash answer different questions from “is this claim correct?” Conflating them is how automation creates false confidence.

Relay can establish
  • Structure — a task, event, evidence, review, or decision matches the declared schema for protocol 0.1
  • Integrity — an artifact’s bytes match its recorded SHA-256 hash under Relay Canonical JSON rules
  • Process completeness — required reviews, reproductions, or remediation steps exist in the chain for the stated risk
  • Disagreement survival — failed reviews and competing findings stay attached; they are not averaged away
  • Authority attribution — which named human accepted, remediated, rejected, or deferred a gate
  • AI disclosure — whether models were used at review/decision boundaries and in what scope
Relay cannot establish by itself
  • Scientific truth — a claim is true in nature or ready for a research canon
  • Method validity — a pipeline is correct merely because it ran and produced files
  • Consensus quality — multiple models agreeing implies correctness (shared prompts, data, or bugs break independence)
  • Model authority — an AI review can self-promote into canonical acceptance
  • Governance replacement — policy, law, ethics, or peer review can be fully automated away
  • Honest provenance — a hash does not prove who authored the content or that inputs were not staged
Example · hash

Two reviewers can both hold a valid hash of the same artifact and still disagree on whether the method answers the task’s acceptance criteria. The hash settles “same bytes?”; the human gate settles “acceptable?”

Example · independence

Switching model brands does not make a review independent if both runs share the same prompt pack, cleaned dataset, or hidden context. Independence is declared and auditable—not inferred from marketing labels.

Example · projection

A green Status card or Slack thread can be rebuilt from Git. If the projection and the validated Git record disagree, the Git record wins. Dashboards never become an alternate authority.

Deliberately not enabled

The safety boundary is part of the product.

Non-goals

Relay is coordination infrastructure, not a truth engine.

  • Not a general autonomous-agent platform
  • Not a replacement for scientific peer review
  • Not a model router that requires enterprise APIs
  • Not a secret-holding static website
  • Not a production multi-tenant service yet
  • Not a replacement for domain law, policy, or professional authority