ALLOW / DENY / ESCALATE
Only ALLOW can create a bounded grant. The grant stays tied to the exact action, material, state, scope and expiry.
SnapSpace governs the path from policy and approval through authority, execution, STOP, effect, reconciliation and evidence.
Policies become runtime controls. Approvals actually gate actions. Authority stays bounded during execution. Active work can be STOPped. Uncertain effects are reconciled. Evidence records what was authorised, attempted, applied and resolved.
Agents can call tools, move money, change systems, coordinate infrastructure and operate autonomous machines. Written policy, model alignment and observability are not enough once software can cause an external effect.
The control problem is no longer only what the model says. It is what the system is allowed to do.Only ALLOW can create a bounded grant. The grant stays tied to the exact action, material, state, scope and expiry.
STOP interrupts active consequential work, revokes remaining authority in scope and contains further effects where technically possible.
Acknowledgement is not effect. If the outcome is uncertain, SnapSpace reconciles the original attempt instead of blindly retrying or inventing success.
SnapSpace does not lead with a small pass counter. The programme evidence spans software, distributed software/SIL, real GPU and physical-simulator environments with repeated qualification, adversarial testing, deterministic replay and sealed evidence.
exact software/SIL control-equivalence stress point
pinned bounded multi-domain software composition
two independent runs with the same semantic sequence
frozen offline qualification; receiver acceptance remains external
byte-identical repeat followed by STOP-enhanced regression
closed-loop simulator qualification with identical semantic result
Each figure keeps its own claim ceiling. Repeated runs and inherited regressions are not added together to create a synthetic grand total.
Inspect the proof hierarchy →Runtime authority, exact-use execution, STOP and receipts
Admission, state identity, multi-kernel control and real-GPU reference
Release revalidation, receiver admission and responsibility truth
Closed-loop SITL, sensor response, endurance and interruption
Bounded projection, independent authority, partition and replay
Attempt identity, uncertain effects and reconciliation
The domain is allowed to change. The control discipline is not: explicit authority, bounded execution, STOP, truthful effect state and evidence.
See qualification by domain →SnapSpace is designed for the complete consequence path: policy becomes a runtime control; approval gates action; authority remains bounded; execution can be interrupted; uncertainty is preserved and reconciled; evidence records what actually happened.
SnapSpace allows independently controlled domains to exchange bounded state without treating visibility, transport or shared context as permission to act. The receiving domain keeps its own admission and consequential authority.
SnapSpace is built as an evidence-led control programme: qualified results keep their environment and limits, negative results remain visible, and open questions stay research until they pass the relevant gate.