Skip to content

Governed continuations

Governed continuations preserve exact deferred work across process restarts and transport changes without turning conversational state into authority. They are an additive AncientOS runtime primitive, stored separately from pending actions, Lich approvals, Zeus evidence, and LifeVault memory.

A record binds a canonical principal, original-goal hash, exact action hash, registered action reference, blocker evidence, bounded applicable offers, conversation scope, nonce hash, expiry, and source identity. Compact rendering shows only the lifecycle and applicable choices. Diagnostic rendering remains bounded and redacted; raw prompts, credentials, secrets, unrestricted policy payloads, and unsafe exception text are not stored.

Selection is never approval. Resume requires current canonical-principal ownership, scope, nonce, action identity, readiness, and separate exact Lich authority. SQLite compare-and-transition semantics provide an exactly-once resume claim. Narrowing or otherwise changing an action changes its hash and therefore requires new authority. Terminal records are retained; there is no background retry, automatic resume, migration scheduler, deletion path, or cleanup policy.

Legacy pending actions and safe pending intents may be projected read-only when their identity and ownership are uniquely resolvable. The source record is not modified. Informal confirmations, missing principals, governance-sensitive intents, ambiguous aliases, and unsupported schemas remain unavailable.

Rubick may establish setting ownership, readiness, reversibility, and amendability. It does not approve or mutate. A policy-amendment choice appears only for a registered, non-secret, reversible, allowlisted Rubick-owned setting with current evidence; policy approval and original-action approval remain separate.