Foundations
Representation (EBSRC)
The Evidence-Bound Supervisory Representation Contract: a deterministic transform from independently authoritative work state to a bounded representation for human supervision.
Three words that carry the contract
Supervisory. The person who delegated can understand the current state, intervene at the moments that matter, and confirm the result of intervening.
Independently authoritative. An agent writing “verified” does not make an input verified. Which system is authoritative for which fact, which records were observed and who approved which scope are established by the application’s contract. Authority of source, accuracy, freshness and fitness of interpretation are separate; authoritative data is not assumed to be reality.
Deterministic. The same Case revision, role, policy version and presentation conditions give the same meaning of facts and the same allowed actions. Colour and layout may vary within bounds. A model swap never turns outcome-unknown into “done” or adds an execute button to a read-only job (INV-14).
Input and output
EBSRCInput {
case, objects, role, sources, observations, claims, interpretations,
proposals, alternatives, decision, executions, verifications, preconditions,
adapters, control, policy,
view: { mode, request }, // what the person is looking at, and what they asked for
access: { reducedMotion, screenReader, zoom, pointer }
}
RepresentationPlan {
caseId, caseRevision, policyVersion, resolverVersion,
mode, systemMode, work, focus,
mustShow, relations, controls, forbidden,
attention: { level, reason }, transitions, reason, announce
}
The plan is not HTML. It is what a renderer must follow: the centre object, the disclosures it may not omit, the relations to explain, the controls with their reasons and bound versions, the completion words forbidden now, the next transitions, and one human sentence saying why this form.
The reason is part of the record
Why Compact became Compare, why authorization is needed, why Recovery instead of a completion. “A new record arrived” is weak. “The quantities compared use different field meanings, so the mapping needs review” is the kind of reason required. The Work Object Shell shows it at the top of every representation, and the live region announces it when the mode changes.
How the resolver chooses
An unsettled outcome outranks everything. Then, in order:
- unknown, partial or failed execution → recover,
- stop requested, or execution in flight → execute,
- applied but not verified → verify,
- an approval whose premise changed → authorize with a re-check,
- a decided proposal that needs approval → authorize,
- an unmet precondition → compare, work blocked,
- real alternatives without a decision → decide,
- a proposal resting on an open or superseded claim → compare, attention requested,
- open claims that nothing depends on → compact, with the pending summary,
- everything verified → compact, resolved.
A person’s request overrides the mode but never the obligations: collapsing keeps what is pending visible, exploring never unlocks a control.
Models may help, inside the contract
Models may interpret and propose. Proposals enter as structured, checkable data: a claim with evidence, a proposed action with a diff and a version. Generated prose cannot declare success, verification or permission around the contract (INV-13, INV-20).
Any input, the same boundary
Input is not only typing. A scan, a file attachment, a record selection, a direct edit, an external event, an approval, a reconnection, another person’s handoff: each changes state. The resolver looks at what the event changed in the work’s meaning, not at how it arrived. A change of the same meaning passes the same policy and the same verification boundary whether it came from natural language or direct manipulation.
People and agents read the same structure
Progressive disclosure for people must not erase meaning for agents. When comparison details are collapsed for a person, the fact that an open claim exists and can be opened stays in the semantic structure. That does not mean putting hidden sensitive data in the DOM: access rules per role still hold. The goal is not the same pixels for both, but non-contradictory meaning in each one’s permitted way of observing.