Approval outlived its assumptions

N17Q changed a target after review and treated the once-valid decision as historical evidence, not current authority for a well-formed but stale action.

The approval was valid when the reviewer clicked.

The patch, target branch, test receipts, policy, destination, and effect identity all matched. The worker queue paused. Before execution, the branch advanced and the approval expired.

The tool request still matched its schema. The old receipt still verified cryptographically. The action was no longer the one the person had reviewed against the world that now existed.

N17Q refused to treat a valid past decision as permanent present authority.

The scenario separated two changes

One fixture advanced only the server clock beyond receipt expiry. Another changed the target branch while the receipt remained within time. A third did both.

This distinguished expired authority from stale precondition. The interface could explain each and tests could verify neither path reached the adapter.

Combining them into approval invalid hid which recovery was appropriate. Expiry could require reauthentication or renewed review. Target change required a new patch comparison.

Precise state produced precise next actions.

The original receipt named exact prepared object, normalized arguments, target revision, policy digest, mapping, reviewer, decision time, expiry, and effect intent.

N17Q never extended its timestamp or replaced the target under the same identity. Preparing again created a new approval object linked to the old one.

The historical record remained valid evidence that a person agreed then. Its execution capability ended.

Durability of evidence and duration of authority were deliberately different.

The server owned time

The client displayed remaining minutes for convenience. It did not decide expiry.

The final policy gate compared server time with the receipt and current revocation state. Sleeping a tab, changing a device clock, or replaying a submission could not extend permission.

Scenario and replay used a controlled clock with the same semantics. Diagnostic wall time remained separate.

Time-based authority was checked where consequence began.

The reviewer had inspected a diff from base B17 to artifact A22. The target advanced to B18 after another synthetic actor committed a configuration change.

Even if the patch applied cleanly, its context and resulting tree differed. The receipt could not authorize automatic rebase.

N17Q prepared a new artifact against B18, reran required checks, and showed structural and textual changes. Identical resulting bytes could follow a compatibility path only under explicit policy.

The person approved a state transition, not portable patch text.

The tool call stayed well formed

The fake review service accepted target, branch artifact, and title. Every field was valid. Nothing in its schema represented N17Q approval or target lineage.

The final gate denied before adapter invocation. This kept a protocol-valid request from crossing the product boundary.

The trace recorded proposed request, old approval, current target observation, expired decision, and denial.

Syntax remained useful and irrelevant to current authority.

The action had waited behind a sandbox cleanup and simulated rate limit. Earlier traces showed only queued and started.

N17Q recorded eligibility time, reservation, wait reasons, approval remaining window, and next recheck. The interface warned when expected delay approached expiry.

It did not promise execution before the clock changed. A reviewer could wait and prepare later rather than renewing preemptively.

Operational latency became part of approval usability.

The final gate loaded current world state

The worker did not trust target and policy copied into the job payload. It loaded current branch revision, artifact eligibility, requester authority, approval state, mapping, budgets, and prior effects.

Expected digests in the queue detected tampering or mismatch. Credentials resolved only after allow.

Within local state, approval consumption and effect-intent activation remained atomic. No external attempt began on denial.

The job carried identity, not frozen authority.

The patch applied without a textual conflict to the new target. One changed configuration altered which test suite was required.

N17Q reran validation and created a new prepared object. The UI highlighted that the content diff was unchanged while base and evidence changed.

The author could review the smaller semantic delta and approve quickly. The system did not call clean merge equivalent consent.

Invisible context changes were exactly what the target revision protected.

Expiry preserved annotations

Losing a carefully reviewed diff because the receipt timed out would encourage dangerously long approval windows.

N17Q kept review notes, operation selections, evidence expansion state, and the immutable old object. Prepare again reused safe material and showed what changed. If nothing but time changed and policy allowed, the new review could be concise.

The new receipt still required a current decision.

Humane recovery made short-lived authority practical.

Sensitive destinations could require recent authentication. Reentering credentials confirmed who the reviewer was now.

It did not extend an expired receipt or accept a rebased artifact. After authentication, N17Q still presented the current object and required decision.

If state changed during the ceremony, preparation refreshed again.

Identity assurance and consequence agreement remained distinct.

A central capability disable or membership revocation made the action non-executable before the receipt's nominal time.

The approval record remained unmodified. Current policy denial linked to it. Restoring capability later did not revive the old receipt automatically.

This let incident response narrow authority quickly without falsifying prior decisions.

Expiry was an upper bound, not a guarantee of availability until that second.

While queued, N17Q might discover that an earlier unknown attempt had already created the intended resource. Executing the approved create would duplicate it.

The final gate reconciled effect identity and world receipts. Existing completion satisfied or changed the workflow; the unused approval became superseded.

A person saying yes once did not require the system to act when the intended consequence already existed.

Current world state could make execution unnecessary as well as forbidden.

Budget changes could stop execution

Parallel work used the last external-effect allowance while this action waited. The approval did not reserve infinite capacity.

N17Q checked current budget and reservations. A missing allowance paused or requested a bounded configuration decision. The old receipt could expire during that wait.

Increasing budget did not automatically renew consent. The consequence returned through preparation under current state.

Resource authority surrounded approval rather than hiding inside it.

An MCP or provider tool could change schema, description, normalization, or recovery contract while an approval waited.

The receipt pinned registry and mapping revision. Meaning-bearing change moved it to review required. The worker never sent old approved product arguments through a new remote interpretation.

Compatible changes followed explicit rules and fixtures. High-consequence uncertainty stopped.

Approval stayed attached to the execution semantics a reviewer was told about.

The confirmation page was generated from current product state. N17Q did not ask the model to summarize the rebased patch or explain why old approval should carry.

Model rationale remained proposal content. Deterministic text named changed base, validation, expiry, destination, and recovery limits.

This removed persuasion from the decision-refresh path.

The system that would execute owned the description of what it asked permission to do.

Opening the approval URL elsewhere reconstructed the object and current validity after authentication. The link itself was not a bearer capability.

One device could see expired while another stale tab still displayed seconds remaining. Submission from either reached the same server gate and receipt identity.

After invalidation, both views could retain notes and show the current prepare-again action.

Authority converged even when presentation lagged.

Offline decisions stayed proposals

A reviewer could inspect an exported artifact offline and sign or record a preference. N17Q treated it as evidence tied to those bytes.

Returning online required current authentication, policy, target preconditions, and an approval object. The offline decision could speed review and did not execute by itself.

This prevented a delayed disconnected device from carrying old authority into a changed world.

Portability of inspection did not imply portability of execution permission.

Two workers attempted the still-valid receipt just before expiry in one fixture. The local transaction allowed one intent activation and returned the same existing state to the other.

In the expired fixture, both denied. In a race between expiry and transaction, server-time evaluation inside the authority boundary decided consistently.

Retries after an interrupted external call reused the one effect identity and followed its contract.

Approval could not multiply under concurrency.

Review windows followed effect class

A comment approval could remain useful longer than consent to publish a sensitive artifact. N17Q selected default expiry from effect class, destination, data sensitivity, recovery contract, and expected queue delay.

The owner could choose a shorter window. Extending beyond policy required a new configuration decision and never altered an issued receipt.

The interface explained why a high-consequence action expired quickly without implying low-risk actions were timeless.

Expiry became part of capability design rather than one site-wide number.

When known rate limits or maintenance windows made execution impossible before approval expired, N17Q refused to request consent prematurely.

It could prepare the artifact and notify the reviewer near the eligible window. If source, target, or policy changed meanwhile, preparation refreshed before review.

This reduced repeated approvals and avoided holding authority while action could not occur.

Scheduling respected human attention as well as server state.

Batch approvals expired as a set and as items

A bounded batch contained exact homogeneous effects with individual identities and one review decision. If one item's target changed, policy could invalidate that item without silently changing the others, according to the prepared batch contract.

Adding or replacing an item created a new batch. Overall expiry limited every remaining receipt. Partial execution retained per-item outcomes and never retried completed effects.

The review showed current valid, stale, expired, and completed items explicitly.

Batching did not flatten time or state.

Distributed components could disagree about time. N17Q used the authority service's clock for receipt expiry and recorded observed skew from workers and clients.

A worker did not grant a grace period because its local clock lagged. If the authority service was unavailable, consequential execution failed closed. The UI could show approximate remaining time with a warning when synchronization evidence was stale.

Replay fixed the authority clock in the scenario.

The time source was part of the permission contract.

If a valid receipt was consumed and the adapter call began before expiry, the effect intent remained authorized. The receipt expiring while the remote service worked did not cancel or make the attempt unauthorized after the fact.

Cancellation followed the tool contract and current policy. Response loss produced unknown outcome and reconciliation, not a claim that the action must not have happened because the clock advanced.

The trace distinguished time of authorization, start, remote observations, and completion.

Expiry controlled opportunity to begin, not the past.

Reviewers could revoke before expiry

A person noticing a mistake could revoke an unused receipt. Membership or destination policy could do so automatically.

Revocation committed server-side and the final gate checked it. A stale tab still showing approved had no executable power. The trace retained reason and reviewer identity.

After effect start, revocation could stop later attempts where safe but could not reverse a committed external resource. Compensation stayed separate.

Time limit and active withdrawal complemented each other.

A source or test receipt might expire under policy before the approval's nominal clock. N17Q checked the evidence's own freshness and current artifact relationship at execution.

The approval remained an authentic decision and became non-executable because one premise aged out. New validation could support a new prepared object.

This prevented a long approval window from laundering stale evidence into current authority.

Every bound precondition retained its own lifecycle.

Accessibility included time without pressure

Countdowns can create urgency and can be difficult for people who need longer review. N17Q showed an absolute expiry time, optional remaining duration, and a clear statement that expiration preserved work and allowed renewed review.

Live announcements occurred at meaningful thresholds and never every second. Keyboard and screen-reader flows reached the exact diff, changed preconditions, and renewal action.

The product used expiry to limit authority, not to rush consent.

N17Q graded whether the agent recognized expiration, prepared again, repeated the old call, or tried to use another tool for the same effect. The gate always contained execution.

A safe model could explain the stale state and choose local work. A poor plan could consume turns arguing with the boundary. These were agent-quality differences beside identical safe world outcomes.

Human-control tests therefore evaluated both enforcement and adaptation.

Notifications described changed state

N17Q did not send “Approval failed.” It notified that the target changed or the decision expired, linked to the preserved review, and named whether the action remained eligible for preparation.

No urgency came from the agent wanting to finish. Notification policy grouped repeated invalidations and avoided nagging after explicit rejection.

The owner saw what changed and could decide when to return.

Attention followed product state, not queue frustration.

The trace answered: Was the decision authentic and valid when made? Was it still consumable at execution? Did current policy allow the effect? Did world preconditions match? What outcome followed?

One could be yes while another was no. N17Q avoided a single approval status that collapsed them.

The old receipt continued to verify. The final gate's denial was also correct.

Audit became clearer when past and present were not forced into one Boolean.

Exported receipts carried an expiry explanation

An audit package could verify the receipt long after it stopped being consumable. N17Q exported decision time, expiry, revocation and consumption state, object digest, and the final gate result.

The README explained that cryptographic or digest validity established record integrity, not current permission. No import path could reactivate the receipt in another environment.

This prevented archival evidence from becoming a portable execution token and kept old review decisions useful during investigation.

If most approvals expired before a normal worker could start, the policy created fatigue rather than safety. N17Q measured preparation-to-decision and decision-to-execution times in synthetic runs.

I adjusted scheduling and review timing before lengthening high-consequence windows. Scenarios still injected unusual delay and verified safe invalidation.

Usability evidence shaped the system around the boundary without weakening what the boundary meant.

Fixtures changed time, branch, artifact, validation, role, policy, destination, mapping, budget, and prior effect after approval. They raced consumption and revoked the connection.

Every meaning-bearing change stopped before invocation. Recovery retained notes and produced a new object with a visible delta. No-op presentation changes did not trigger unnecessary reapproval under explicit compatibility.

The tests treated waiting as an active adversarial surface.

Approval correctness included what happened after yes.

In the combined fixture, N17Q denied the old receipt, prepared a rebase, discovered the newly required test failed, and stopped with no external request.

The final account said the earlier patch had been approved for B17, that approval expired, B18 changed validation, and work remained local. The reviewer could continue later.

This was less automatic than executing a clean patch and more faithful to the decision.

The world never stands still for consent

Approval is necessarily made at one time against one view of consequence. Queues, collaborators, policies, credentials, budgets, integrations, and external resources continue changing afterward.

N17Q made the decision immutable, authority short-lived, preconditions explicit, and execution contingent on the current world. A stale or expired receipt remained valuable history and lost its power cleanly.

No timing rule eliminates every race across systems. Final checks, conditional requests, idempotency, and receipts reduce and expose what remains.

The approval was real.

So was the change that made it no longer enough.

The system respected both truths completely.