Portability and authority

Bolt-On Demonstrator

Continuity should survive the host. Execution should not move into the sidecar.

Claim boundary: this page records a verified software-development trajectory and a proposed integration path. It does not claim a production ChatGPT plug-in, arbitrary-host compatibility, or completed end-to-end Cognitive Basin integration.

Frozen v0.3 evidence

Verified / Frozen
  • frozen at commit 0176545bc2a5ea3db296779aea909d3ae3f682c1
  • 20-file frozen release
  • two independent host families
  • one live substitution
  • 48 adversarial cases rejected
  • bolt-on actions executed: 0

v0.4 external-host contract

Built and locally validated
  • read-only sidecar registry and removal neutrality
  • separate command boundary
  • 73 local tests, including rejection cases
  • execution authority remains NONE
  • not yet described here as production integration

Canonical separation of responsibility

Read, project, replay - but do not execute.

  • Host: owns native state and native execution.
  • Adapter: identifies, normalizes events, and projects portable actions.
  • Permit boundary: accepts or rejects exact one-use host permits.
  • Receipt substrate: records evidence, decisions, checkpoints, and replay digests.

No arrow flows from the adapter directly to native execution.

A host authority boundary diagram showing the read-only adapter, permit boundary, and host-owned native execution.
The architectural result is bounded continuity, not sidecar sovereignty.

Replay and substitution

Portable semantics

Portable actions remain bounded to HOLD and RELEASE-like semantics rather than assuming every host exposes the same native command names.

Checkpoint and replay

Receipts and checkpoints make substitution auditable. A later host can resume portable state without rewriting earlier evidence.

Immediate external-host pilot

The next bounded experiment is a real external chat host with an untouched baseline, a read-only adapter, exact receipts, and host-owned action gates.

Exact non-claims

  • The current frozen release is not a direct ChatGPT plug-in and has not been installed into OpenAI hosted infrastructure.
  • The qualified fixtures do not prove compatibility with every API, workflow engine, operating system, or cloud environment.
  • The work does not establish machine consciousness, selfhood, moral agency, or autonomous authority.
  • The work does not prove zero drift. It proves replay and bounded invariants inside the declared fixtures and attack classes.