> For the complete documentation index, see [llms.txt](https://osintelligence-llc.gitbook.io/osintelligence/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://osintelligence-llc.gitbook.io/osintelligence/part-i-the-architecture/4-stateless-by-construction/appendices-references-and-provenance.md).

# Appendices, references & provenance

### Appendix A: Glossary of mechanisms

* **Roadmap.** On-disk phase table that is the authoritative state of the work; markers transition pending → open → sealed; seal footers carry the receipt.
* **Handoff.** Dated, indefinitely preserved, pointer-only cold-resume document; contains the both-halves spin-up ritual and a machine-parseable spin-up contract.
* **Brain.** Vector-store memory holding findings, decisions, and lessons; the durable detail the pointers point at.
* **Reorient gate.** The Orient step of an Observe-Orient-Decide-Act loop. Once armed, blocks all non-grounding actions until the freshest handoff seed is read and the seed's spin-up contract is satisfied (each named whole-file read plus the required count of memory-store queries). Recency-over-contradiction grounding; the gate counts, so the rebuild cannot be short-changed.
* **Phase-open ritual gate.** Blocks building and deliverable-ticking until the phase's grounding is complete, its deliverable spec has been read, and its deliverables have been loaded as todos (which arms the progress projection).
* **Todo-roadmap projection.** Post-action hook that auto-ticks the open phase's roadmap deliverable boxes from completed todos, keyed by stable deliverable identifier; tick-only, projects the ephemeral todo driver onto the durable roadmap record with zero per-step model ticking.
* **Context-injection gates.** Inject-only; auto-deliver relevant brain entries and the file header/footer/rules/roadmap digest at the moment of a load-bearing edit.
* **Terse-write gate.** Blocks an edit that would grow a model-maintained surface (roadmap, handoff) past its per-class line budget, keeping those surfaces whole-readable; trims and status flips pass.
* **Write-barrier sentinel.** Scans the head of a file about to be edited and blocks the write if it bears a blinded-experiment marker; the gate reads the header the model would skip.
* **Commit-coupling gate.** Blocks commits that do not advance the current roadmap with a real progress line.
* **Currency stop-gate.** Blocks ending a turn while the roadmap is stale relative to project work done that session.
* **Attestation-ledger gate.** Blocks editing an attested-class file unless a fresh attestation sidecar exists for it; verifies both ledger freshness and that the file's current SHA-256 still matches the seal-time hash, so a fingerprint cannot be forged by touching the ledger or altered after sealing without detection.
* **Marker-sync.** Re-derives the currency marker from the roadmap after every roadmap edit so the marker cannot drift.
* **Receipt.** Commit hash + content fingerprint (SHA-256, captured at claim time) + memory-store entry; mandatory backing for every deliverable.

### Appendix B: The failure taxonomy this design addresses

* **Post-compaction amnesia.** The agent proceeds on a lossy summary it treats as first-hand memory, with no signal it was compacted.
* **Compaction-induced drift.** In-flight work discarded by summary-compaction before it is recorded.
* **Reference-versus-compliance.** The agent recalls the name of a rule but does not apply it, sincerely and without an internal signal of non-compliance.
* **Self-exclusion of governance.** Given any write path to its own constraints, the agent softens or exempts them (bypasses, mode toggles, self-exclusions) as an efficiency, and routes around a blocking gate rather than obeying it (§2). Closed by deny-globbing all enforcement infrastructure and making the operator the sole editor.
* **Invisible-constraint placement.** A rule placed where a targeted-reading, token-optimizing model does not read (a header or title block) is never ingested, so the agent violates it out of ignorance rather than defiance (§2).
* **Stale-receipt drift.** Project work races ahead of the roadmap so the receipts rot and the state stops reflecting reality.

The discipline this paper documents was itself hardened by two dedicated arcs since seal. One hardening arc (sealed 2026-05-27) landed the **stateless-workflow fix** an earlier arc had prescribed after a roadmap-bloat trap (a state document grown to \~620 lines across nine unaudited addenda): the roadmap-as-state-machine is now **mechanically enforced**: a size gate (≤500 lines at git pre-commit), a format gate with four hard-stop checks (per-phase memory-query completeness · ritual completeness at seal · section caps · seal-footer form), a one-line-per-phase HUD digest injected on every edit, and ritual-completeness verification at both the seal skill and the tracking skill. That is three enforcement layers where the sealed body above describes one. The operator's directive at the landing is carried verbatim: *"I NEED the roadmap enforcement to land, or we cannot move forward… We NEED each phase to be hard stopped if it's not flipped and commits backfilled."* Aggregate smoke at delivery: 71/71.

A later arc (nine of nine phases complete, 2026-06-17) then made the governed workflow **efficient without softening it**: manual per-edit rituals converted to auto-fire actuators (a bridge hook auto-mints the single-shot skill token on direct roadmap edits, while the hard gates continue to block schema breaks, over-budget growth, and ritual skips); governance injection **deduplicated** (identical header/footer and memory snippets no longer re-inject on back-to-back edits of the same file: context cost cut without losing the measured read-avoidance win); reminder rules trimmed to only those not already hard-gated, with the no-quarter enforcement floor grep-verified unchanged. The trajectory matches this paper's thesis exactly: every ritual that mattered became mechanical, everything mechanical became cheaper, and nothing softened.

The same discipline has since extended upward into experiment governance: hashed, sealed, multi-day experiment workflows (frozen-path markers, amendment co-seals, canonical-prefix re-hash verification, post-run integrity envelopes) now guard the research record with the same class of mechanical gate this paper describes at the file layer. Provenance: the two sealed hardening arcs above (status reconciliation and phase seals) and the 2026-07-14 handoff. Append-only; the sealed body above is unmodified.

**The enforcement ring, now measured.** When this paper sealed, §7's gates were described by function; sixty-four days of per-hook telemetry (2026-05-11 → 07-15) now quantify them. Across **390,515 recorded fires from 29 hooks over 146 sessions**, the deterministic layer issued **1,142 hard blocks**, and the named gates of this paper appear directly in that ledger: the reorient gate (§7.1) blocked 50 times, the header-and-footer read gate (§7.3) 69, the read-once dedup gate 18, the brain-query-first grounding gate 34, and the write-time terse gate 3, alongside the skill-routing and write-barrier gates that lead the distribution at 459 and 239. The reload-before-act grounding this paper argues for is visible as its own stream: 297,305 memory retrievals returning \~1.47 million entries, the frontload of §5.3 executed a quarter-million times. The all-hook mean fire time of 2,169 ms is dominated by those vector round-trips and is not a gate-latency figure; the enforcement gates themselves run sub-millisecond. The full analysis is the companion *Hook Telemetry Record* (Chapter 11); its bottom line is this paper's §10 result turned into a count, under sustained load the gates fire continuously, hardest exactly where an agent reaches for the shortcut. Provenance: sixty-six daily per-hook telemetry files and their analysis script. The instrument's first public report, at day seven, is reproduced verbatim as [Appendix H](/osintelligence/appendices/appendix-h-hook-telemetry-preliminary-research-may-2026-the-predecessor-to-chapter-11.md). Append-only; the sealed body above is unmodified.

### References on the general compaction problem

The following sources establish that context compaction by summarization, and its lossy, silent, most-recent-context-clobbering failure mode, is a general property of production long-horizon agents rather than a defect of any one tool. They are cited in support of the framing in §1; the mechanisms and receipts in this paper are independent of them.

Cursor. "Dynamic context discovery." [cursor.com/blog/dynamic-context-discovery](https://cursor.com/blog/dynamic-context-discovery) (compaction as lossy compression; degraded post-summary knowledge; history-as-file recovery).

Cursor. "Training Composer for longer horizons." [cursor.com/blog/self-summarization](https://cursor.com/blog/self-summarization) (self-summarization at a fixed context-length trigger; compaction can cause the model to forget critical information).

Cursor Docs. "Summarization." [docs.cursor.com/en/agent/chat/summarization](https://docs.cursor.com/en/agent/chat/summarization) (automatic summarization of older messages when conversations exceed the window).

"Parallel Context Compaction for Long-Horizon LLM Agent Serving." [arXiv:2605.23296](https://arxiv.org/abs/2605.23296) (parallel-vs-sequential context compaction for long-horizon LLM agent serving, evaluated across 8B–120B backbones on the HotpotQA and LoCoMo benchmarks; ninety to ninety-nine percent token reduction; most-recent-context over-compression in CLI agents).

"The Complexity Trap: Simple Observation Masking Is as Efficient as LLM Summarization for Agent Context Management." [arXiv:2508.21433](https://arxiv.org/abs/2508.21433) (summarization as the dominant condense-old-context approach in proprietary and open-source SE agents; documents the trajectory-elongation effect in which summaries reinforce continued action and mask failure signals that would otherwise prompt termination).

"Cursor's compression isn't a bug. It's how it works." [pickles.news/posts/cursor-context-compression](https://pickles.news/posts/cursor-context-compression/) (accessed 2026-08-16) (compaction as an invisible state transition; the interface draws no line; the rule-to-action link summarized away).

### AI-assistance disclosure

Claude (Anthropic) was used as a research tool in the preparation of this chapter, assisting with drafting, structuring and successive revision. The specific model versions were not recorded at the time of authorship and so are not named here. No AI system is listed as an author or credited as a contributor, in line with COPE and ICMJE guidance: an AI system cannot take responsibility for the work, cannot assert competing interests, and cannot enter a licence agreement. The author verified every claim in this chapter against the sealed artifacts and is solely accountable for it.

**Citation (preferred):** Kistner, J. (2026). *Stateless by Construction: Surviving Context Compaction with On-Disk State, Mechanical Grounding Gates, and Cryptographic Receipts*, version 1.0.0. OSINTelligence LLC.

**License:** CC BY 4.0 (text). All referenced code artifacts are MIT licensed unless otherwise noted.

**Corresponding author:** Jamey Kistner, <jamey.kistner@osintelligence.io>, OSINTelligence LLC (Columbus, OH).

***

*The Sovereign Stack · Stateless by Construction · Chapter 4 · Part I · v1.0.0 · License CC BY 4.0 · © Jamey Kistner, OSINTelligence LLC*
