Distributed Cognitive Network
Volume V
DCN Runtime Specification 0.1
Part 3A
Agency Runtime and Patch Proposal Protocol
71. Purpose
This specification defines the runtime model for Agencies, the Patch Proposal Protocol, execution contracts, lifecycle management, and the interaction between Agencies and the Cognitive Kernel.
Agencies are the runtime execution units of DCN Runtime. They are not independent cognitive systems. They are specialized processes that operate on behalf of a Mind.
72. Design Philosophy
Traditional multi-agent systems often give each agent its own memory, state, and decision loop. DCN Runtime instead places authoritative state and scheduling under the Mind and Cognitive Kernel. Agencies perform bounded work.
73. Agency Definition
An Agency is:
A persistent, specialized execution process that performs bounded cognition or actions while operating over the shared world state owned by the Mind.
Examples include Planning, Research, Communication, Scheduling, Compiler, Evaluation, Medical, and Travel Agencies.
74. Agency Responsibilities
An Agency MAY observe world state, retrieve K-lines, invoke experts, execute artifacts, produce plans, generate patches, evaluate alternatives, and request capabilities.
An Agency SHALL NOT directly mutate world state, bypass authority, permanently own truth, or independently redefine goals.
75. Agency Contract
Every Agency SHALL declare a contract containing purpose, capabilities, required inputs, expected outputs, authority requirements, side-effect policy, resource limits, lifecycle policy, and failure semantics.
The contract is static; execution is dynamic.
76. Agency Context
At execution time the Cognitive Kernel provides the relevant goal, world-state slice, working memory, authority context, budgets, time constraints, capability bindings, and execution policy.
Agencies MUST NOT infer authority from context merely because information is visible.
77. Shared World Model
All Agencies reason over the same logical world. They never maintain competing authoritative copies. Local caches are permitted; authoritative state belongs to the Mind.
78. Immutable Inputs
Execution begins from a consistent snapshot. The Agency reasons against that snapshot and produces proposals. The Cognitive Kernel later determines whether the assumptions remain valid against current state.
79. Agency Output
The primary state-changing output is a PatchProposal, not direct mutation. Pure or observational Agencies MAY also return ordinary execution results without proposing state change.
80. Patch Philosophy
A Patch is a proposed semantic modification to the world model. It is not a database transaction, SQL update, arbitrary object mutation, or imperative code.
81. Patch Categories
Semantic operations may include Create, Update, logical Delete, Link, Unlink, Schedule, Authorize, Recommend, Reject, and Escalate. Rich domain operations SHOULD be preferred over generic CRUD when semantics are known.
82. Patch Schema
Conceptually:
{
"schema": "dcn.patch-proposal.v1",
"id": "patch:...",
"origin": { "agency": "planning" },
"base_state": "sha256:...",
"operations": [],
"justification": {},
"required_authority": {},
"dependencies": [],
"expected_effects": [],
"confidence": 0.94,
"created_at": "..."
}
The canonical machine-readable wire schema is defined by the Cognitive ABI schema registry; this example is informative.
83. Operations
Operations SHOULD be semantic. Examples include CreateTask, CompleteTask, ScheduleMeeting, RecommendMedication, AttachEvidence, LinkEpisode, and PublishArtifact.
84. Patch Justification
Every Patch SHALL explain why it exists. Justification MAY reference ExecutionActs, EvaluationActs, K-lines, evidence, goals, and observations.
85. Patch Confidence
Confidence estimates expected correctness. Confidence does not grant authority. A patch with confidence 0.98 still requires authorization where policy demands it.
86. Patch Dependencies
A Patch MAY depend upon other patches, authority, remote execution, human approval, evaluation, or time. The Cognitive Kernel resolves dependencies before commitment.
87. Patch Validation
Validation is independent of generation and checks schema, authority requirements, consistency, conflicts, policies, constraints, and required evidence. Validation SHALL NOT silently rewrite a Patch.
88. Patch Authorization
Authorization answers whether the proposal may change the world. It may involve user approval, delegated authority, organization policy, Actum-recorded authority, or cryptographic credentials. Generation and authorization remain separate.
89. Patch Commitment
Committed patches become part of the world model. Rejected patches may remain historical but inactive.
90. Patch Lifecycle
created → validated → authorized → committed → observed
Alternative terminal states include rejected, expired, conflicted, and cancelled.
91. Patch Conflicts
Conflicts occur when two patches rely on incompatible assumptions or propose incompatible state. Both patches may be individually valid. Conflict resolution occurs before commitment.
92. Conflict Resolution
Resolution MAY use priority, merge, new planning, System 2, human review, or policy. No universal strategy is mandated.
93. Agency Lifecycle
registered → idle → scheduled → running → waiting → running → completed → idle
Terminal or administrative states include failed, retired, and disabled.
94. Scheduling
Agencies do not self-schedule. The Cognitive Scheduler activates them, preserving coherent resource allocation.
95. Agency State
Persistent Agency state SHOULD remain minimal: configuration, statistics, cached bindings, and temporary checkpoints. Durable knowledge belongs in the shared Mind.
96. Memory Access
Agencies access memory through runtime interfaces rather than directly manipulating storage engines. This preserves auditing, policy enforcement, caching, and synchronization semantics.
97. Capability Requests
Agencies request cognition through CapabilityRequirement. They do not directly choose providers. The Cognitive Kernel performs local resolution and MAY consult Actum Compute.
98. Nested Agencies
Agencies MAY request additional Agencies. The Cognitive Kernel tracks parent-child causality and enforces recursion and resource policy.
99. Failure Semantics
Failure SHALL produce an explicit error and SHOULD preserve policy-permitted partial outputs, diagnostics, and learning signals.
100. Retry Policy
Retries depend on failure type. Network failure may retry; authority denial normally does not; validation failure may require System 2; provider unavailability may trigger alternative resolution.
101. Checkpoints
Long-running Agencies SHOULD periodically checkpoint working memory, active bindings, pending patches, and progress to enable recovery.
102. Cancellation
Cancellation SHALL be explicit. Cancelled Agencies MUST release attention, compute, reservations, and bindings. Partial patches remain uncommitted.
103. Observability
Agencies emit runtime events such as AgencyStarted, AgencyPaused, PatchCreated, CapabilityRequested, ExecutionCompleted, and AgencyFailed.
104. Security Boundary
Agencies SHALL operate with least privilege. Capabilities and authority are granted explicitly. No Agency possesses universal authority.
105. Determinism
Deterministic Agencies SHOULD produce equivalent Patch Proposals given identical inputs, world snapshot, and configuration. Non-deterministic Agencies SHOULD declare that property according to the Cognitive ABI determinism model.
106. Composability
Agencies compose through events, capability requests, results, and patches—not through ungoverned shared mutable state.
107. Strategic Observation
DCN Runtime Agencies are not miniature people. They are specialized cognitive processes coordinated by the Cognitive Kernel, sharing one coherent world model, proposing semantic patches instead of mutating state, and contributing execution history from which future cognitive capital may be learned.