Skip to main content

Research / Multi-Agent Systems

Runtime safety for multi-agent AI systems

A bounded research program for shared authority, delegation, coordination under partial failure, and independently checkable effect evidence.

Research object

Three bounded research hypotheses

The unit of analysis is the complete multi-agent workflow, not an isolated agent or tool call. Each hypothesis can fail under the declared model; a counterexample rejects the corresponding claim.

C1

Shared approval admission

Test at-most-one successful authorization admission across heterogeneous executors under declared races, duplicates, crashes, recovery, and partitions.

C2

Approval–decision–effect safety

Test the coupled invariant under explicit failures, bypass attempts, evidence failure, clock uncertainty, and ambiguous destination outcomes.

C3

Omission-aware effect evidence

Independently check causal evidence while distinguishing attempted, accepted, committed, observed, and unknown effect states.

Claim discipline

Current product boundary

Quiet Open-Core v1.2.0 is the current public baseline: fail-closed interception, deterministic policy, bounded human approvals, sandboxing, and local hash-chained evidence. It provides an experimental foundation; it does not by itself prove the MAS hypotheses.

Broad novelty, exactly-once external effects, production-qualified multi-tenancy, and complete evidence are not claimed. Final claims depend on a source-by-source comparison, a declared failure model, specialist review, and independent evaluation.