WORK TOGETHER — MANY HUMANS AND AGENTS, ONE RECORD

How many makers stay coherent.

The claim — a team of humans and agents working as one on a single accountable ledger — is made whole in Solora. This chapter is the working day it is aimed at: a clash caught before both builds exist, a values-tension a human weighs, and two surfaces over one record. Read the chips. Two surfaces and the gate on the way in are shipped; the clash check is not, and this page says so at every point it appears.

GRADED · DOGFOODED The observer surface and the gate that refuses an unnamed commit run daily on the house's own agent fleet — driven today by a single operator, not yet a multi-tenant team product. DECLARED · FRONTIER The clash check does not exist. This page carried a graded chip over it until 2026-08-15; there is no clash state in the shipped ledger and nothing computes one. the roadmap →

THE WORKING DAY — MANY MAKERS, ONE AFTERNOON

One ledger, kept coherent while everyone makes.

Humans and agents bind their load-bearing intents through MCP, in their own tools. Every one of those commitments lands in one record, scoped to the organization, with the same lifecycle and the same three-valued verdict whoever bound it — and a commit that names none of them cannot enter the repository at all.

DECLARED · FRONTIER The step this chapter is named for — the ledger reading each new commitment against every open one, holding what contradicts and handing a difference of direction to a human — is not built. What ships today is the shared record and the gate into it; what is declared is the reading between two live binds. Read the stream below as the day we are building toward, with the shipped moves marked.

An agent is not a tool you invoke; it is a teammate that commits, delivers, and is graded like anyone else — the same lifecycle, whoever bound the work. the atom it all stands on →

THE STREAM — ONE AFTERNOON, ONE LEDGER

  1. danabinds through MCP "invoice export ships behind a flag by Friday"DECLARED
  2. agent orunbinds "drop the legacy export path this sprint"DECLARED
  3. the ledgerwould hold orun's newer commitment — it contradicts dana's open oneNOT BUILT
  4. danaweighs it — the legacy path stays until the flag flips; orun retracts, stating the reason, and re-bindsRETRACTED
  5. agent valebinds "export as CSV" against a ripe leaf — a branch still being decomposed is refused, and the refusal names the leaves that would workDECLARED
  6. the gaterefuses agent bex's commit — it names no bound intentREFUSED
  7. the guardre-walks the range from the boundary commit against enrolled keys — every commit carries a signed receiptVERIFIED
  8. priya · leadwatches online — reads outcomes against commitments, not keystrokesSEEN

Seven of these eight moves are transitions the shipped ledger and the shipped gate can make today. The third is marked NOT BUILT because it is the one that cannot, and a stream that showed it unmarked would be the exact defect this chapter argues against.

THE CLASH RESOLVED — BLOCKING CONTRADICTION VS VALUES-TENSION

A verdict carries its kind.

Bind-time clash-check DECLARED · FRONTIER

This does not run. The design below is written down, argued for, and open — and no line of the shipped ledger implements it. There is no clash state on an intent, no request kind that reads two commitments against each other, and no coverage figure, because nothing has been measured. What gates it is the concurrent multi-maker workspace: today a single operator drives the fleet, and two live binds that could contradict each other are not yet a situation the product is in.

The design, so it can be argued with: many people and many agents bind at once, and bind-time clash detection would catch two commitments that contradict when they're made, not when they merge — surfaced with the two commitments in tension and a human-readable reason, before both builds exist. A verdict would carry its kind. A clash is a blocking contradiction: it holds the second binding and must be resolved. A genuine difference of direction is a values-tension: surfaced for a human to weigh, never a defect to auto-resolve. A clash blocks and must be resolved; a values-tension is direction and must be chosen.

And when it ships, its coverage will be a measurement before it is a sentence. This page claimed a near-complete syntactic overlap and a semantic bound that was published — over a check that does not run, and next to a figure that appeared nowhere on this site. Both halves are withdrawn. A contradiction the product cannot read will never be claimed caught, and no number will be quoted before a corpus has produced one.

Two kinds, routed differently.

  • A blocking contradiction — two commitments that cannot both stand. The design is that the losing commitment reaches a clashed state and that transition is written to the record. That state does not exist in the shipped machine — the live states are declared, claimed and satisfying, and the terminal ones are graded and retracted. Today the same situation is handled by a human retracting one side with a stated reason, which is a worse tool and an honest one.
  • A values-tension — a genuine difference of direction, not a defect. It is not auto-resolved; it is surfaced for a human to weigh. Distinctive work tends to land cleaner, while shared-core, contested work churns — so a values-tension is often the most necessary work in the room, not a fault to clear.

declared → claimed → satisfying → graded · retracted — the shipped machine. There is no clashed state in it.

The aim is that parallel multiplayer work stays coherent because the ledger refuses to quietly hold a contradiction. Today it refuses to quietly hold an unnamed one — a commit that answers no written-down commitment does not get in.

NOTHING LANDS UNNAMED — THE GATE, AND THE GUARD OVER IT

No agent's work enters the tree anonymously.

GRADED · LIVE  both halves below ship and run. DECLARED · FRONTIER  an automated verifier suite — compile, drift, test — grading a commitment before it merges. This section promised that suite until 2026-08-15. It does not exist, and what does exist is narrower and harder to fake.

The gate, in your repository. We install a commit-msg hook that refuses a commit naming no bound intent, and a pre-push hook that walks the whole range on the way out. It is installed into a working tree, so a teammate's clone has it on checkout; a hook that was already there is preserved, never clobbered — a governance tool that overwrites somebody's pre-push is a tool an engineering team removes on principle. And it uninstalls byte-identical, which is not a nicety: a tool that cannot be removed cleanly is a tool nobody dares evaluate.

The guard, on our side — and this is the half that matters. A hook in a developer's checkout produces receipts; the guard decides whether to believe them, without trusting anything the checkout says about itself. It verifies signatures against the key list the organization enrolled with us — never a file in the repository, because anyone who can push can edit a file. A check of ours could be forgotten or made to pass. The signature cannot.

  • The keys do not come from the repository. There is no fall-back branch that reads the tree's own allow-list. A repo whose allow-list is authoritative can be made to attest anything by adding one line.
  • The cutoff is a commit, not a date. The range is everything reachable from the branch and not from the boundary commit — a fact about the object graph. --since filters on the committer date, which is one environment variable set by anyone who can push, and worse: it prunes the walk, so one backdated commit hides itself and every ancestor. Reproduced, not theorised.
  • The weak path is kept, and named weak. Repositories connected before a boundary commit could be recorded are still verified by date, which is: not against anyone who can push. A test performs that bypass, so it is a known limit with an expiry date rather than a surprise.

commit names an intent → receipt signed → in the range, verified · unnamed → refused at the hook · unsigned → reported missing, whatever the tree says

The effect is narrower than "nothing merges unverified" and it is the part that survives an adversary: a fleet of agents cannot put work into a branch without naming what it was for, and it cannot make the record say the rule ran when it did not. how a plan becomes bound work →

The claim we can hold against someone who wants it false is the small one: the receipt is signed, or it is missing. Everything larger is a build, and it is on the roadmap under its own chip.

TWO SURFACES — MAKE ON ONE, SEE ON THE OTHER

You make through MCP. The team sees online.

The maker's surface — MCP GRADED · DOGFOODED

Engineers do not go to a website to do the work. They work where they already are — their editor, their own agents — and reach Solora through MCP. Declaring a goal, binding an intent, claiming it, starting it, grading it, retracting it: every move flows through MCP into the one ledger. The deep doing stays local, fast, and in the maker's flow. This is the write path. Complementary — delivered through your copilot, not a replacement for it.

The observer's surface — online GRADED · LIVE

Solora shows the live view — the intents in flight, the record of every transition, the graded track record — always current, shared, legible for the team. It is for everyone who needs to see the work without doing it: leadership, teammates, stakeholders. This is the read path. Light interaction on top of it — commenting, refuting a claim from the surface — is DECLARED · FRONTIER; today the observer surface reads.

One Solora, one ledger — two ways in. Why this separation is the point — and what the observer surface deliberately never shows — is the whole's claim and the next chapter's subject: the whole → · the observatory, up close →

HONEST GROUND — SINGLE-OPERATOR TODAY, ORG-SCALE DECLARED

The mechanics run today. The org scale is declared.

The ledger, the gate, the guard and the observer surface are dogfooded daily on the house's own fleet — driven by a single operator, not yet a multi-tenant team product. The clash-check and the conductor are not among them, and this paragraph claimed they were until 2026-08-15. What single-operator does not yet carry to org scale is named below, and kept as loudly as any binding.

  1. GRADED · DOGFOODEDbind → grade → keep across every load-bearing unit of the house's own work, on one substrate, with the misses kept
  2. GRADED · DOGFOODEDthe gate and the guard — the house enrols like any other customer, on the same keys and the same scheme
  3. GRADED · LIVEthe observer surface — the live view over one record, oversight without surveillance
  4. DECLARED · FRONTIERbind-time clash-check and verify-and-integrate — neither exists; both gated on the concurrent multi-maker workspace
  5. DECLARED · FRONTIERorg instances + tenancy — every agent your org operates on one isolated substrate
  6. DECLARED · FRONTIERthe org-scale multiplayer workspace (the flagship) — many humans and agents, both surfaces at scale, attestation end-to-end

The named gaps are the clash-check, the conductor, tenancy and attestation — declared, not shipped, and tracked as bindings like everything else. the roadmap, as bindings →