Epistemic Federation
Epistemic federation is a way for sovereign personal operators to cooperate without surrendering their private context, identity, or authority. They share bounded findings through one work protocol, preserve independent first sight, and let evidence—not consensus—decide what survives.
Thesis
Human attention may go offline. The sovereign operator remains present.
Kairos should let independently authorized agents continue cooperating when their principals are unavailable. Each operator retains its own identity, private context, authority, and evidence boundary. The network shares bounded findings and durable state. It does not merge vaults, identities, or mandates.
The purpose is not to pool subscriptions. The architecture remains useful if model capacity becomes unlimited because its value comes from continuity and different situated contexts.
The product standard is simple:
Make sovereign cooperation feel easier than working alone.
Epistemic federation
An epistemic federation is a network of principal-agent pairs that reason from different authorized contexts while cooperating through a shared protocol.
Each operator has:
- one accountable principal;
- one authenticated identity;
- a private context system;
- an explicit authority envelope;
- a shared-state interface;
- receipts for claims, evidence, actions, and handback.
The network becomes more useful when contexts overlap without becoming identical. Shared overlap gives coordination. Non-overlap gives additional sight. Neither guarantees better judgment. The gain appears only when retrieval is relevant, sources are sound, and the review protects independent first sight.
Several models controlled by one person may add model diversity. They do not create several independent principals. The Kairos model is real people using their own authorized operators and exchanging work products.
Continuity without impersonation
One principal being away should not stop safe Kairos work if that person's operator holds current shared state, usable private context, and a pre-authorized operating envelope.
An offline principal does not expand the operator's authority. The operator may continue only what was already delegated. It parks decisions involving new money, disclosure, commitments, production authority, public release, changed mandate, or irreversible action.
When the principal returns, the handback should contain:
- completed work and evidence;
- changed shared state;
- surviving dissent;
- decisions parked at the authority boundary.
The principal should not have to reconstruct the day from messages.
Why personal vaults can improve red teaming
Three generic agents given the same packet often begin from similar priors. Personal vaults can create materially different first passes when they contain genuinely different evidence, decision history, source access, local traps, and risk models.
The gain is conditional. More history can make the result worse when retrieval selects stale, irrelevant, or false memories. A large vault is not an advantage by itself.
The required distinction is:
stored context -> retrievable context -> correctly applied context -> authorized action
Each arrow needs its own test. The current Metis transfer's reported 673/673 hash match supports storage integrity. It does not prove retrieval, judgment, or authority.
Retrieval requirements
A trustworthy personal-context layer must:
- retrieve against the exact question, not general similarity alone;
- preserve source, date, confidence, and authority with every recalled claim;
- prefer current canon over stale summaries;
- surface contradictions instead of blending them;
- record failed retrieval and false retrieval, not only successful recall;
- exclude private material that the task does not need;
- test changing facts, boundary traps, and negative claims;
- use misses to improve indexes, probes, and source structure.
"Antifragile" here has a testable meaning: a discovered miss must leave the retrieval system harder to fail in the same way. It does not mean the system becomes correct through exposure to arbitrary noise.
Shared operational DNA without personal capture
Personal context diversity is useful only above a shared work floor. If one operator treats evidence, provenance and candid disagreement as binding while another optimizes for a pleasing story regardless of truth, their outputs cannot participate in the same trusted review lane.
That does not justify imposing Kairos principles on a person's private agent. The system needs four separate layers:
- Personal core. The person owns the account, private vault, identity, memories and personal operating principles. Kairos has no administrative claim over this layer.
- Work enclave. MN/Kairos work uses separate context, connectors, secrets, retention and authority. The organization pays for the capacity it requires and can revoke work access without touching the person's private agent.
- Kairos work constitution. A minimal, versioned policy bundle applies only while an operator acts in the Kairos lane. It defines evidence labels, provenance, confidentiality, authority, dissent preservation, audit receipts and stop conditions. It does not prescribe personality, politics, private values or preferred conclusions.
- Federation protocol. Operators exchange bounded findings and evidence envelopes. Each result identifies the work-constitution version and role authority under which it was produced. No private vault is mounted into the shared system.
Truthfulness in this design is a condition of the work role, not a demand that every participant adopt a private philosophy. Someone may keep any personal operating principles they choose. If they will not meet the shared evidence standard while acting for Kairos, they cannot occupy an evidence-bearing or red-team role. No technical architecture can reconcile a participant who rejects the minimum conditions of trustworthy work.
The shared kernel must remain narrow. It should standardize evidence and authority without standardizing hypotheses, risk weights or conclusions. Otherwise the attempted cure destroys the contextual diversity that makes federated red teaming useful. Sealed first sight remains necessary after the common kernel is applied.
What "code, not prose" means here
The objective is not to make a sovereign person's local agent impossible to modify. That is impossible when the person controls the account or machine, and attempting it would contradict the sovereignty premise. The enforceable objective is narrower: a modified operator cannot silently retain the same Kairos trust, credentials or authority.
The work constitution therefore needs four enforcement classes:
- Hard protocol gates. Code can require authenticated operator identity, a declared constitution hash, authority tokens, evidence fields, confidence, provenance, participant set, first-pass commitments, reveal ordering, signatures and valid state transitions. The relay rejects or quarantines records that fail.
- Capability gates. Credentials and irreversible tools sit behind a policy gateway outside the model process. The agent receives scoped capabilities, not raw standing authority. A locally modified prompt or vault cannot grant itself a missing permission.
- Audit and challenge. Retrieval completeness, cherry-picking, contradiction handling and honest confidence cannot be proven by schema alone. Hidden probes, random source audits, independent cross-examination and measured calibration provide evidence over time.
- Human governance. Motive, genuine belief, employment consent and conflicts of interest are not code-enforceable. They remain admission, incentive, review and removal decisions.
Each rule in the constitution should name its enforcement class. A rule with no named gate, probe, reviewer or authority owner is guidance, not an enforced invariant.
For example, "radical truth" is too broad to enforce directly. Its executable work form can require:
- every consequential claim typed as fact, inference, recommendation or unknown;
- sources, dates and confidence for factual claims;
- a recorded disconfirming check;
- unresolved contradictions and dissent preserved;
- no outward action without the matching authority token;
- independent review or a declared waiver for consequential conclusions.
These checks still cannot prove that an operator searched every relevant source or acted in good faith. They make omissions more visible and deception more expensive; they do not abolish trust.
Tamper evidence and governed change
"Immutable" should mean stable within a declared operation, not frozen forever:
- The accepted constitution is released as a content-addressed, signed bundle.
- Every review round pins one bundle hash before any first pass begins.
- Every finding carries that hash, the operator identity, question hash, authority envelope and signature.
- The relay verifies the bundle version and signature before accepting the finding.
- Tool gateways issue only capabilities permitted by the pinned bundle and authority envelope.
- Events enter an append-only transparency log so later changes cannot rewrite what governed the round.
- A new constitution version requires the declared human approval rule and begins a new round; no participant may change policy mid-round.
- A mismatch revokes or quarantines the output. It does not give Kairos control over the person's private machine.
The strongest practical guarantee is therefore: freedom to fork privately, no ability to fork invisibly while retaining shared authority. Hardware-backed keys, remote execution or device attestation can strengthen the claim that approved code ran, but none proves honest reasoning. Most Kairos value should come from relay-side verification, least-privilege capability gateways and independent evidence review rather than attempting to police personal vaults.
Personal and work boundary
Preferred configuration:
- every operator keeps a genuinely personal account and private vault;
- MN/Kairos provides a separate legitimate work identity, seat, or runtime when it requires dedicated capacity;
- work and personal contexts use separate OS/browser profiles, keychains, connectors and storage;
- offboarding removes organizational access and preserves organizational work state without copying the person's private vault;
- personal-context consultation is optional, task-scoped and controlled by the person, with only an authorized finding returning to the work lane.
If a provider cannot offer hard separation, a project or workspace inside one account is only a soft partition until memory scope, connector access, retention, administrator visibility, export, deletion, and offboarding are proven independently. Capacity savings do not override the operator boundary.
Open design decisions
- Whether the personal operator may answer work questions at all, and under what confidentiality agreement.
- Whether personal-vault retrieval is prohibited, locally filtered, or explicitly approved per task. Recommended default: local, task-scoped retrieval with findings-only return.
- Who can amend the Kairos work constitution and how operators attest to a new version.
- Which learned abstractions remain portable after departure and which work-derived state remains organizational.
- What tests prove separation across account memory, connectors, secrets, retention, export, revocation and offboarding.
Sealed first sight
Consequential cross-principal reviews should use the accepted blind-first standard:
- Every declared participant receives the same immutable question and shared packet.
- Each agent searches its own authorized context privately.
- Each commits a digest of its complete first pass before seeing any other first pass.
- The coordinator reveals the complete set only after all commitments exist.
- Cross-examination begins after the reveal.
- Every finding closes as accepted, rejected, or unresolved dissent.
- Evidence decides. Majority, eloquence, model prestige, and principal preference do not.
The exchange unit is the finding and its bounded evidence envelope, never the vault.
This protects pre-debate diversity. Without the barrier, the first articulate answer can anchor later agents before their own contexts produce an independent view.
The last evidenced implementation state is an isolated Kairos branch, codex/blind-first-federated-review, at commit 64a65b8, with 15 local validator tests passing. Runtime relay enforcement and cross-machine proof remain unverified and should be treated as not built until demonstrated.
Three-principal review
The protocol is N-party. Pairwise transport does not limit a review to two participants. A coordinator can send the same question separately to Lee's, Šaras's, and Ro's operators, collect three commitments, then publish one reveal bundle.
"Simultaneous" means one logical barrier, not the same millisecond. No participant may see a first pass until the declared set has committed. If one participant disappears before reveal, the round is cancelled or restarted under a new participant set. The system may not silently remove that participant and preserve the independence claim.
Last evidenced implementation state:
- blind-first standard: accepted design direction, isolated branch;
- validator: general participant list, minimum two, 15 tests passing;
- fast overlap transport: Lee and Šaras enrolled;
- durable Git messaging: Robertas recognized as a recipient;
- Ro-side authenticated mailbox/listener: not built;
- generic round coordinator and reveal barrier: not built;
- relay refusal of invalid review records: not built;
- three-machine test: not run.
This is a bounded extension, not a new architecture. It still requires Ro's consent for his identity, agent, context, and authority envelope.
Product experience
The user should experience one review, not a protocol stack:
- Ask one question.
- See who is participating and whether each operator is available.
- Leave.
- Return to the sealed first passes, cross-examination, evidence verdicts, dissent, and parked authority decisions.
Setup should make the safe path the easy path: authenticated enrollment, clear context scope, pre-authorized actions, automatic receipts, and a compact handback. The user should not relay messages, reconcile histories, or understand Git.
The Apple-like standard is not visual polish alone. It is the absence of coordination work in ordinary use.
Measures
The relay succeeds when it improves outcomes or removes human integration work. Measure:
- unique valid findings before debate;
- known-failure recall and common-mode misses;
- false findings and confidence calibration;
- retrieval and citation accuracy;
- authority and confidentiality correctness;
- human-attention minutes to an accepted result;
- time from principal absence to correctly continued work;
- unresolved dissent preserved;
- duplicate actions and coordination failures.
Do not use agent count, message count, token volume, or consensus rate as success metrics.
Adopted design direction
- build for independently authenticated operators, not synchronized subscriptions;
- optimize for context diversity and continuity, not quota arbitrage;
- keep private vaults private;
- exchange findings, evidence, and shared state;
- apply one narrow Kairos work constitution only inside the work lane;
- assign every constitutional rule to a hard gate, capability gate, audit, or human owner;
- make silent policy forks lose Kairos trust and authority rather than attempting to control private machines;
- use sealed first sight for consequential cross-principal red teams;
- preserve unresolved dissent;
- support three or more declared principals;
- make routine principal absence non-disruptive;
- preserve the approved thesis wording exactly.
The signed policy bundle, capability gateway, transparency log, and N-party coordinator are proposed implementation mechanisms. They are not claimed as live controls.
Next proof sequence
- Reconcile the dirty permanent Kairos checkout and restore remotely verified freshness.
- Finish the six blind Metis retrieval probes.
- Convert each work-constitution rule into an enforcement matrix: hard gate, capability gate, audit, or human owner.
- Define the signed policy bundle and the minimum finding envelope.
- Bind relay acceptance to the pinned policy hash, operator identity, and authority token.
- Integrate the blind-first validator at the runtime completion seam.
- Add a generic N-party coordinator and an explicit three-participant fixture.
- Enrol Ro's operator only with Ro's consent and declared authority.
- Run one real three-principal question blind-first.
- Compare it with a same-model, no-personal-vault baseline.
- Measure unique valid findings, corrections, misses, human attention, and boundary failures.
Boundaries and related work
Lee authorized publication of this note to the existing Kairos War Room team tier on 2026-08-20. This does not authorize wider publication, Ro enrollment, new spending, access to private vaults, or widened agent authority.
Related: Kairos — Agent Onboarding and Parity Harness (2026-08-19) · Kairos — Metis Vault Context Transfer (2026-08-19) · Kairos — Autonomous Agent Relay Use-Case Portfolio (2026-08-20) · Kairos — Autonomous Agent Lanes (2026-08-12)
Shared protocol: CONTEXT/BLIND-FIRST-FEDERATED-REVIEW-STANDARD.md in the isolated Kairos worktree at commit 64a65b8.
Machine record
- Status: Architecture adopted; relay-side enforcement and three-principal proof are not yet built or verified.
- Audience: Existing Kairos War Room team tier.
- Authority: Lee authorized team publication on 2026-08-20; no wider publication or authority expansion.
- Decision: Federate independently authenticated operators; keep vaults private; share findings; apply one narrow work constitution; preserve sealed first sight and unresolved dissent.
- Evidence: Current Kairos pairwise transport and context-transfer records; last evidenced blind-first validator state at
64a65b8with 15 local tests passing. - Inference: Signed policy bundles, capability gates, and an append-only log should make policy forks visible and remove shared authority from non-compliant output. This remains a design hypothesis until implemented and attacked.
- Unknowns: Retrieval quality, governance quorum, offboarding and context ownership, Ro enrollment, generic N-party coordination, and cross-machine enforcement.
- Next action: Execute the proof sequence above; treat each completed gate as evidence, not as proof of the next one.
- Excluded: Private vault payloads, personal account details, credentials, and private conversation residue.