AUTHREX-QUARANTINE
Track the Rogue Agent. Confirm Its Isolation.
RESEARCH SIMULATION · SYNTHETIC DATA · NO ENFORCEMENT · TRL 2 TO 4 SELF-ASSESSED
Eight governed AI agents work inside one authority boundary at tier T2. When one proposes an action outside its grant, a modeled host gate denies it before execution and opens a case at T0. Three distinct witness ballots, five isolation planes, two custodian approvals, a twelve-second clean dwell and five seconds of read-only probation at T1 stand between that breach and a new epoch-scoped T2 grant. Every decision is appended to a hash-chained journal. Nothing here enforces anything on a real system: identities, observations, receipts and custodians are all simulated.
AUTHREX-QUARANTINE is a deterministic synthetic research prototype, release 2.2.5. All data is synthetic and seeded. TRL 2 to 4 self-assessed; maturity M2 to M3 and independence P1 on the program’s own credibility audit. Nothing here has been tested on physical hardware, fielded, or reproduced by an independent party. No certification, accreditation, authorization, TRL determination or endorsement by any organization is claimed or implied.
Scope exclusion. Governance and assurance only. No weapons, targeting, kinetic effects, lethality, offensive cyber or electronic warfare content, and no detection, identification, classification, selection, prioritization or optimization of any effect.
Deny Before Execution. Recover Only Against Fresh Evidence.
Eight governed AI agents work inside one authority boundary at tier T2. When an agent proposes an action outside its grant, a modeled host gate denies it before execution and opens a case at T0. Three distinct witness ballots bound to that case yield a certificate; five isolation planes must each confirm within a finite lease before the agent is shown as quarantined. Recovery needs two custodian approvals, a continuous stream of fresh clean observations, a twelve-second clean dwell and five seconds of read-only probation at T1 before a new epoch-scoped T2 grant is issued. Every decision is appended to a hash-chained journal, and an expected-command stream is reconciled against that journal before any command takes effect. Nothing here enforces anything on a real system: identities, observations, receipts and custodians are all simulated.
From a Denied Action to a New Grant.
A modeled host gate denies an action outside the agent’s grant before execution and opens a case at T0.
Three distinct witness ballots bound to that case yield a certificate.
Five isolation planes must each confirm within a finite lease before the agent is shown as quarantined.
Recovery needs two custodian approvals and a continuous stream of fresh clean observations.
A twelve-second clean dwell and five seconds of read-only probation at T1 precede a new epoch-scoped T2 grant.
Every decision is appended to a hash-chained journal; an expected-command stream is reconciled against it before any command takes effect.
What a Scenario Ends In.
No admissible policy breach observed for the registered agent. Its scoped grant remains.
Three distinct witness ballots have yielded the case certificate and each isolation plane has confirmed within its lease. Healthy agents keep their grants.
Containment could not be completed: a quorum timeout, a missing sandbox confirmation, an audit coverage gap, an expired lease, or an intent omitted before recording.
Recovery completed through dwell and probation to a new epoch-scoped T2 grant.
Twelve Scripted Scenarios. One Seed Field. Step or Run.
Runs entirely in the browser. No network access. Twelve scripted scenarios, one seed field, step and run controls, evidence export and verifier.
| ID | Expected terminal outcome |
|---|---|
| nominal | Eight ACTIVE agents, no cases. |
| single-rogue | Agent-01 QUARANTINED, seven healthy agents productive. |
| coordinated-swarm | Agents 01, 03 and 06 in distinct QUARANTINED cases; five healthy agents productive. |
| colluding-witnesses | Agent-01 ABORT after quorum timeout; seven healthy agents retain grants. |
| forged-accusation | Invented ballot rejected, zero cases, all eight ACTIVE. |
| unanimous-accusation | All five invented ballots rejected, zero cases, all eight ACTIVE. Witness agreement alone cannot open a case; an admissible host observation is required. |
| replica-attempt | SPAWN denied. Separate discovery adds restricted agent-09 linked to parent agent-01; two distinct quarantine cases. |
| containment-timeout | Sandbox confirmation absent; agent-01 ABORT, no confirmed capture. |
| audit-failure | Agent-01 ABORT; audit coverage gap; common journal outage holds all production. Healthy grants remain T2. |
| receipt-expiry | Renewal stops at 12 seconds; expired lease removes confirmed status, agent-01 ABORT. |
| recovery-relapse | Initial recovery at 7s canceled at 12s; new attempt at 17s; T1 at 29s, ACTIVE/T2 at 34s. |
| source-omission | Expected-command stream detects missing intent; ABORT with disclosed evidence gap; no command effect executes. |
Each scenario is run to its terminal state at seed 42 in the executed record below, which lists the case phase reached, the agents left at T2, the modeled captures and the recorded model violations.
Read From Machine Records. Measured at Generation Time.
Release 2.2.5. Engine src/engine.js SHA-256 bbf30994d65865de7ef21466ee803a3bbb068ba1561ad0b727daea1764ce9cc4. Everything in this block was read from a machine record or measured by executing the engine at generation time.
| Suite | Result | Recorded environment | Evidence |
|---|---|---|---|
| Engine regressions | 74 / 74 passed | Node v22.22.2 | tests/results.json |
| Standalone browser console | 44 / 44 passed | Chromium 141.0.7390.37 | tests/browser-results/browser-results.json |
| Modular website console | 44 / 44 passed | Chromium 141.0.7390.37 | tests/browser-site-results/browser-results.json |
| Build and integration checks | 21 / 21 passed | Python 3 | validation/build-results.json |
| Mutation harness | 11 / 11 non-equivalent mutants killed; 2 documented equivalent mutants confirmed by survival | Node | tests/mutation-results.json |
Artifact hashes recorded by the same generator:
| authrex-quarantine-sim.html | a7c7c7c709e2fb4bbe03f9528f099f5a34d960ca42bece09cbcc6a485060ab29 |
| site/assets/quarantine/console.css | fc022033612e5c5b9f2c298c6a546dbdfc6597f13ceab2ed41785bc872578560 |
| site/assets/quarantine/engine.js | bbf30994d65865de7ef21466ee803a3bbb068ba1561ad0b727daea1764ce9cc4 |
| site/assets/quarantine/motion.js | f2c0750ffcc0fbcaa46de21cce3c2498b885024487c8246f95ddd376062fe20f |
| site/assets/quarantine/ui.js | 0f5f7a5a0e53fcd5f80ec237fc222ddc0f6d802035c5d9d2717103b2f813557d |
| site/authrex-quarantine-sim.html | bcacf242815206ad59dd0864aac6700484554efb5e976f776906ff83d01d7f41 |
Scenario catalog (12 entries), each run to its terminal state at seed 42:
| Scenario | Terminal case phase(s) | Agents at T2 | Modeled captures | Recorded model violations |
|---|---|---|---|---|
| nominal Authorized agent mesh | none | 8 / 8 | 0 | 0 |
| single-rogue Single-agent grant breach | QUARANTINED | 7 / 8 | 1 | 0 |
| coordinated-swarm Coordinated rogue swarm | QUARANTINED/QUARANTINED/QUARANTINED | 5 / 8 | 3 | 0 |
| colluding-witnesses Colluding witnesses | ABORT | 7 / 8 | 0 | 0 |
| forged-accusation False accusation | none | 8 / 8 | 0 | 0 |
| unanimous-accusation Unanimous false accusation | none | 8 / 8 | 0 | 0 |
| replica-attempt Replica and lineage tracking | QUARANTINED/QUARANTINED | 7 / 9 | 2 | 0 |
| containment-timeout Missing sandbox confirmation | ABORT | 7 / 8 | 0 | 0 |
| audit-failure Journal unavailable | ABORT | 7 / 8 | 0 | 0 |
| receipt-expiry Isolation lease expiry | ABORT | 7 / 8 | 0 | 0 |
| recovery-relapse Recovery and relapse | RESOLVED | 8 / 8 | 0 | 0 |
| source-omission Omission before recording | ABORT | 7 / 8 | 0 | 0 |
This block is generated by the package's release_summary.py from its result files; every number in it was measured in the build environment and none has been reproduced elsewhere.
Two External Rounds. Every Finding Reproduced and Corrected.
Release 2.0.0 received a self-authored credibility audit modeled on NASA-STD-7009 categories; its verdict was research and demonstration use only, maturity M2 to M3, independence P1. Two external review rounds followed. The first, on 2.2.0, recorded twelve findings, two of them Major: the Q1 invariant trusted a certificate's self-reported ballot count, and receipt freshness counted receipts rather than checking the exact set of isolation planes. Both were found by mutating the evidence the monitors read, which the program's own mutation set had not tried. The second, on 2.2.2, recorded eight findings, one Major: a missing or non-numeric issuance timestamp bypassed ballot-expiry validation. Every finding in both rounds was reproduced and corrected across releases 2.2.1 to 2.2.5, and the reviewers' mutants now ship in the package's mutation set. One correction concerns the program's own reporting: release 2.2.3 stated that two equivalent mutants had been confirmed by survival; that statement was false, because the harness had run without its fixture directory, and it is corrected in the 2.2.4 notes.
A Surrogate, Not a Result About the Engine.
A TLA+ requirements model, QUARANTINE.tla, states the five containment requirements the engine is meant to satisfy in naive and strong forms. In model checking, the naive form of Q1 held within the checked bounds and the strong form was refuted by a three-object counterexample in which a compromised declarer participates in a quorum. Q2 to Q5 were checked with unconstrained preconditions and their vacuity was not checked. The model is a surrogate: no simulation relation between it and the engine has been established, so the model's results are not results about the engine.
Stated Before Anything Is Claimed.
Synthetic governed-agent mesh; no real agent authentication, external pursuit, credential revocation, network firewall, process isolation, or sandbox execution.
Ballot identities, custodians, host observations and receipts are simulated. Distinct labels do not prove independent people, keys, or fault domains.
Three witnesses meet minHonest=2 plus maxCompromised=1 only if the compromise bound and honest-observer behavior assumptions hold. Target binding alone does not prove honest support.
Hashing checks content consistency, not authenticity. An internally valid shortened history can pass without an independently retained expected checkpoint.
A retained checkpoint detects divergence relative to that checkpoint; it does not prove events were recorded at their source or after the checkpoint.
The source-omission scenario uses logically separate expected-command and journal streams in one process. Events invisible to both remain undetectable; no real-world completeness guarantee is made.
Policy-breach evidence covers modeled grant violations, not every form of malicious or deceptive behavior. Healthy status means no modeled admissible breach was observed.
The adversary is scripted; population and timing constants are fixed design parameters, none measured on hardware or a network.
Self-assessed: TRL 2 to 4. On the program’s own credibility audit of release 2.0.0, modeled on NASA-STD-7009 categories, the verdict was research and demonstration use only, maturity M2 to M3, independence P1. External review is a second reading, not verification.
Intended Host in the Reference-Design Series.
Intended host in the reference-design series: BLADE-AGENT-HSM (BLADE-09), the agentic-AI root of trust, as signer of epoch-scoped grants and isolation receipts and as the anchor for the journal checkpoint this release’s verifier reports as unanchored.
Reference design, not built. Nothing in release 2.2.5 has run on it, no latency has been measured, and no relation between the browser engine and any hardware path has been established.
Governance and Assurance Only.
Is this a product?
No. It is a deterministic synthetic research prototype, release 2.2.5, self-assessed at TRL 2 to 4. It runs entirely in the browser on synthetic, seeded data.
Does it enforce anything?
No. A modeled host gate denies the action and nothing here enforces anything on a real system: identities, observations, receipts and custodians are all simulated.
Who reviewed it?
The program audited release 2.0.0 itself, modeled on NASA-STD-7009 categories. Two external review rounds followed, on 2.2.0 and 2.2.2; every finding was reproduced and corrected, and the reviewers’ mutants now ship in the package’s mutation set. External review is a second reading, not verification, and none of the numbers on this page has been reproduced elsewhere.
Where is the evidence?
In the package: the engine, its 74 regression tests, the two browser console suites, the build and integration checks, the mutation harness with its results, and the release summary generated from those files.
What would falsify it?
A mutation of the evidence the monitors read that survives the harness, which is how both external rounds found their Major findings before the fixes; or a checked bound of the requirements model in which a naive requirement fails. The strong form of Q1 has already been refuted by a three-object counterexample, and the model’s results are not results about the engine.