Exploration note
The deployment boundary was only a place
Agents can bypass the physical handoff between execution and runtime, so authorization, evidence, and reconciliation have to attach to each consequential action instead.
Agent workflow / Published Jul 19, 2026 / Revised Jul 22, 2026
- Project: vuoro
- Vuoro
- The public label for this family of small, separately owned agent-workflow tools.
CI/CD did not solve the boundary between execution and runtime. It made one particularly convenient version of that boundary governable.
The software moved in stages. A person edited a representation of the system, an artifact was built, and a pipeline carried that artifact into an environment where it could take effect. The crossing was visible enough to acquire gates: tests, review, signatures, promotion rules, deployment records, and rollback. The industry became good at guarding the bridge because there was a bridge.
An agent acting through an operational API has no corresponding journey. It can diagnose a failing workload and change it through the same session. It can read a customer case and answer the customer. It can find a malformed row and repair the table. It can inspect a campaign and alter its audience. In each case the medium of execution is already the place where the consequence occurs. There is no artifact waiting politely at the edge of production.
This is not peculiar to AI. Operators, support staff, database administrators, and traders have always worked this way. Agents generalize their condition: more organizational work becomes direct manipulation of live state, performed at machine speed through reusable interfaces.
The physical planes collapse. The semantic distinction must not.
An attempted action and a durable consequence are still different facts. An API call may time out after committing. A message may be sent but never delivered. A controller may accept a new declaration without converging on it. A contract may be signed while its obligations remain unperformed. Calling all of this one “operational plane” would describe the topology while throwing away the exact distinction an audit needs.
The replacement for the old crossing is an action envelope:
intent
+ work reference
+ pinned governing context
+ authenticated actor
+ scoped capability
+ target and preconditions
-> attempted action
-> observed consequence
-> reconciliation
The capability is the before-boundary. It says which action may be attempted, against which target, for how long, and under which preconditions. It should be short-lived enough that possessing yesterday’s context does not grant today’s authority.
The receipt is the during-boundary. It binds the action to the work, session, actor, capability, request, target, and immediate result. A generic session trace is useful evidence but too weak as the contract: it can explain a run without proving that the run was entitled to change anything.
Reconciliation is the after-boundary. It asks whether the intended consequence actually holds and whether it continues to hold. This is not merely review after the damage. High-risk actions can still require a proposal, simulation, transaction, second principal, or reversible staging step before execution. What disappears is the assumption that every useful control can sit at one universal handoff called deployment.
The smallest durable unit therefore changes. In an artifact pipeline it was
reasonable to make the deployment the main audit object. In direct operation it
has to be the consequential action. Session logs remain valuable, but a session
is only a container. One session may read freely, acquire two different
capabilities, attempt five mutations, observe three consequences, and leave one
ambiguous result for repair. Compressing that into session: succeeded would be
the new version of closing a ticket when its pull request merged.
This also changes what “runtime” means. It is not a synonym for a Kubernetes cluster or a deployed executable. Runtime is the durable field of consequences: the live service, the altered ledger, the sent reply, the published price, the active contract, the customer promise. Execution is the attempt to intervene in that field. They can occupy the same system and still require different records.
For Vuoro, the implication is narrower than building an organizational control plane. Claims and sessions already point in the right direction, but a wider substrate would need to bind capabilities and consequence receipts to stable work and knowledge references without becoming the owner of every target system. The target still decides what happened. The work system still decides why it mattered. The substrate preserves the causal join.
CI/CD gated the crossing. Agents often do not cross. What remains gateable is the action, and what remains provable is the path from authority to consequence.
Optional exploration template
Portable task language, not part of the note.
A post-hoc prompt for applying and extending this note. It is not a reconstruction of how the note was written.
This note is superseded by "Authority must travel with the action", which merges its argument with the access-cell boundary and owns the current guidance; read that first. This note remains the origin record for one half of it. The transferable question: when work can take effect where it is executed, what happens to the controls that used to attach to a crossing? The worked answer is that the smallest durable unit changes. Where an artifact pipeline could make the deployment the main audit object, direct operation has to make the consequential action the unit -- a session is only a container, and compressing one that acquired two capabilities, attempted five mutations, and left one ambiguous result into a single success flag is the new version of closing a ticket when its pull request merged. It also separates runtime from execution: runtime is the durable field of consequences -- the live service, the altered ledger, the sent reply, the active contract -- while execution is the attempt to intervene in it, and the two can share a system while needing different records. High-risk actions can still require proposal, simulation, a second principal, or reversible staging; what disappears is the assumption that every control fits at one universal handoff. Apply the question to a workflow that no longer crosses a boundary. Name your unit of audit and what a session-level success flag would hide. Say where your constraints diverge, then read the successor and say what it adds.