diagnostic"Nobody Owns the Specification" (standalone tentpole, draft v17, "Your Agents Have Owners. Your Policy Has No Author.")Read the article
The Specification Authorship Record
The check resolves a versioned reference, or it fails.
Ratified
2026-09-09
License
CC BY 4.0
Cite as
Webber, 2026
View raw
- title
- The Specification Authorship Record
- slug
- specification-authorship-record
- objectNumber
- 12
- version
- 1.0
- status
- published
- type
- diagnostic
- source
- "Nobody Owns the Specification" (standalone tentpole, draft v17, "Your Agents Have Owners. Your Policy Has No Author.")
- lastUpdated
- 2026-09-09
{
"title": "The Specification Authorship Record",
"slug": "specification-authorship-record",
"objectNumber": 12,
"version": "1.0",
"status": "published",
"source": "\"Nobody Owns the Specification\" (standalone tentpole, draft v17, \"Your Agents Have Owners. Your Policy Has No Author.\")",
"sourceArticleUrl": "https://medium.com/enterprise-experience-architecture/your-agents-have-owners-your-policy-has-no-author-8d8f7264d3f4",
"summary": "The instrument that answers what an enforcement manifest — an ACS manifest, for instance — doesn't: who ratified it and against what authority; which State Inventory rows it governs and which it declined; what severity tier applies and who verified it, independent of who proposed it; what triggers an amendment. One page, versioned alongside the manifest it governs, bound to it by a pre-merge check that resolves a specific Record version or fails — an attestation does not satisfy the check, and N/A does not resolve. The gate does not stay locked when production is actively failing: a five-item provisional-resumption checklist, a watched commitment date, and a standing line item on an executive's own report keep that path from becoming a quiet, permanent workaround.",
"lastUpdated": "2026-09-09",
"changelog": [
{
"date": "2026-09-09",
"version": "1.0",
"note": "Published (Build Ledger item 52). The article's live Medium URL is confirmed by direct fetch — title, byline, and publish timestamp all match, and the live article text links directly to this object's own page from two places in its body, point-for-point consistent with the 0.2 reconciliation pass. `sourceArticleUrl` set to that confirmed URL. Status/version flip only — no content changes in this entry, matching Object 3's, Object 6's, Object 7's, and Object 11's own draft-to-published precedent (0.x drafts flip to 1.0 on publish, regardless of the draft's own last minor version)."
},
{
"date": "2026-09-09",
"version": "0.2",
"note": "Content reconciliation against v17 (Build Ledger item 50) — the source article was superseded between the 0.1 authoring pass and this one. Added `provisionalResumption` (the five-item resumption checklist and its context/boundary/fallback notes), `commitmentTracking` (the two-week alert and second-miss escalation), and `visibility` (the standing line item on the executive's quarterly report) — none had a counterpart in the v7-sourced build. Sharpened question 4's `whatItRequires` with the second trigger's detection mechanism (one shared, versioned constraint ID per override, in a single aggregated log a standing query watches). The binding rule, the State Inventory columns and discovery-source targets, questions 1–3, both cross-links, and `howToRun` checked out as unchanged against v17 and were carried forward. Still `status: \"draft\"`, still no `sourceArticleUrl` — this is a content pass only, not a publish-flip."
},
{
"date": "2026-08-24",
"version": "0.1",
"note": "Initial authoring, staged as draft per every prior object's own practice of author review before a page goes live, and per Build Ledger item 46 / ProjectBrief v2.17's build-ahead-of-publication plan. `sourceArticleUrl` deliberately omitted — the source article is not yet live, confirmed by pre-flight check, matching Object 5's deploy #1 pattern. The binding rule, all four questions, and the closing self-test are extracted directly from the article's own text, not reconstructed from Build Ledger item 46's summary of it. Cross-linked to the Authority Audit (Object 3) and the Amendment Protocol & Veto Charter (Object 5), both as plain-text mentions in the article's own framing. Not yet published: pending author review of this object's own editorial framing, and pending the source article's Medium URL going live (the publish-flip trigger, Build Ledger item 46)."
}
],
"type": "diagnostic",
"tagline": "The check resolves a versioned reference, or it fails.",
"specificationAuthorshipRecord": {
"bindingRule": "The binding rule that makes it real is the one this framework uses everywhere it gates a merge: the check resolves a versioned reference, or it fails. The manifest carries a resolvable reference to a specific version of its Record. A pre-merge step resolves that reference and verifies the Record's content against the certification it claims. An attestation does not satisfy the check, and N/A does not resolve.",
"questions": [
{
"question": "Who ratified this, and against what authority?",
"whatItRequires": "A name, a role, and the scope of specification that role is empowered to certify. Not \"reviewed by Security.\" Reviewed is not authored, and a reviewer's signature on someone else's assumptions transfers nothing."
},
{
"question": "Which states does this manifest govern, and which did it decline to govern?",
"whatItRequires": "Bind the manifest to specific rows of the State Inventory — a five-column enumeration, no fewer: the state in operational language, the trigger condition that puts the system in it, what the agent must and must not do while it holds, the cost if it renders wrong, and where the state was found. Every row translates one-to-one into a constraint block. The declined list matters more than the governed one — an explicitly unhandled state is a known risk; a silently unhandled state is the nine days nobody counted."
},
{
"question": "What severity tier applies, and who verified it?",
"whatItRequires": "Whoever proposes the tier does not get to be the one who confirms it. A self-classified severity is a self-graded exam. Check the claim against the constraint library and the override telemetry, not against the submission."
},
{
"question": "What triggers an amendment?",
"whatItRequires": "Three, in order: regulatory change, structural signal — three squads overriding the same constraint — and production incident. Anything else is a preference request and gets returned at intake, unreviewed. That second trigger only fires if someone can actually see three squads doing the same thing across silos — every override resolves to one shared, versioned constraint ID in a single aggregated log, and a standing query, not a person, watches that log for the third instance. The full mechanism, including who may halt a live surface and what ends the halt, is published as the Amendment Protocol and Veto Charter (Standard object 5)."
}
],
"howToRun": "Run it against one manifest already in production. If any of the four comes back blank, the manifest is enforcing a specification nobody wrote. If you want the same test one level up — aimed at the organization rather than at a single manifest — the Authority Audit (Standard object 3) is five questions built the same way, where the failing answer is the diagnosis.",
"provisionalResumption": {
"contextNote": "It does not stay locked when production is bleeding, and the mechanism that keeps it from staying locked is not \"certify the Record in 24 hours\" — that would be exactly the pressure that gets a Record falsified to close a ticket, and it isn't what's asked.",
"checklist": [
{
"title": "Governed behavior on record",
"description": "The failing state has some governed behavior on record, even if provisional."
},
{
"title": "Cost and severity assigned",
"description": "Its cost and severity are assigned, not deferred."
},
{
"title": "Fallback specified",
"description": "A fallback is specified for that one constraint."
},
{
"title": "Named ratifying function signs off",
"description": "A named ratifying function — not SRE, not the on-call engineer — signs off."
},
{
"title": "Dated commitment logged",
"description": "A dated commitment is logged to finish the real authoring later."
}
],
"boundaryNote": "That checklist explicitly does not require a complete State Inventory, a full adjacent-states audit, or anything resembling the finished Record. It authorizes resumption. It does not pretend to substitute for certification, and nobody is asked to pretend otherwise under deadline.",
"fallbackNote": "Where the fallback for that specific state was ratified in advance, there is an even faster path: the surface returns to it automatically the moment Ops confirms the incident is contained, with no live signature required in the critical path at all — because the decision was already made, ahead of the emergency, by someone with standing to make it. Where no fallback exists yet, a named ratifier has a published response window and a pre-named alternate if the first is unreachable, and a missed window is flagged the next business day as its own incident, not absorbed quietly. Either way, the emergency response and the governance response stay sequential — SRE stops the bleeding on its own clock, on its own authority, and the provisional record catches up without ever asking an on-call engineer to write something that isn't true yet."
},
"commitmentTracking": "That commitment date is watched, not trusted to memory — an alert fires to the ratifying function two weeks before it's due, and a missed date is logged as missed the moment it passes, not discovered months later during an audit. A second consecutive miss on the same commitment escalates automatically to a single named executive, outside the normal renegotiation path.",
"visibility": "An inbox alert with no revenue attached to it gets delegated to a PMO the same afternoon, so the escalation has to land somewhere an executive can't quietly hand it off. It doesn't arrive as a message; it arrives as a line item — every open CRITICAL gap and every unresolved miss is a standing entry on the quarterly report that same executive already reads for liability posture, the same document that reports coverage and exposure. Missing it once is an operational fact. Missing it twice is now visible on the instrument that measures what the organization is exposed to, next to every other number that already gets board attention."
}
}