ora-0155

13.7 Safety invariants beyond scalar regret

A scalar loss can price a violation after it occurs, but it does not by itself make a forbidden composite impossible. In UODL, safety should first be an invariant subcategory \(\mathcal S\), a subobject of admissible histories, or a contract preserved by the action and information maps. Numerical risk observers can then compare admitted trajectories, but they must not replace admission.

This leads to four theorem obligations for agentic UODL:

  1. realization: infer the actual information category from communication, shared state, delegated jobs, credentials, and external effects;

  2. closure: prove that admitted generators remain admitted under team composition and persistent reuse;

  3. observability: prove that the audit functor is faithful on the executions relevant to the invariant and that no relevant channel lies outside its domain; and

  4. intervention: construct stop, veto, revocation, and rollback maps that are natural across delegation and remain effective after the information shape changes.

The last obligation is deliberately stronger than placing a stop token in a prompt. A resilient intervention must commute with handoff and delegation, revoke derived authority as well as its source, and produce an independently auditable witness. Its full treatment belongs with the repair and transport theory of Parts VI and VII.

Guiding question.

Under what hypotheses does a safety invariant survive endogenous refinement of an information category, including newly discovered communication arrows, delegated background processes, and persistent shared artifacts?