Valid approval, stale target

N17Q separated consent from world-state eligibility after an exactly approved patch targeted a resource that changed before execution.

The approval receipt was valid. N17Q still refused to act.

The reviewer had approved exact bytes, destination, recovery contract, and policy. While the task waited in the queue, the target document moved to a new revision. Applying the approved patch would either fail, overwrite another change, or land in a context the reviewer had never seen.

Consent had not expired. The world it referred to had.

I split approval from precondition so each could keep its own identity, check, and failure language.

Approval answered one question

The receipt established that an eligible person had reviewed a materialized consequence and consented to it under a declared policy and time window.

It did not prove that the target still existed, the source remained current, the account retained permission, the budget was available, or an earlier effect had not already happened.

N17Q stopped calling approval the final step. It was one required predicate at the execution gate.

A valid yes could coexist with a necessary stop.

Each consequential capability declared facts that had to hold at invocation: target revision, resource ownership, artifact digest, destination resolution, connection state, effect uniqueness, budget reservation, and policy eligibility.

N17Q materialized these facts with the candidate and marked their freshness requirements. Some were immutable references. Others needed observation immediately before action.

The final gate evaluated them without asking the model to compare prose.

Execution became conditional on both consent and current reality.

Target revisions prevented silent overwrite

For document updates, normalized consequence included resource identity and expected revision. The adapter used a conditional request where supported. Local patch application used snapshot digests and exact context.

If the target changed, the provider returned a conflict or the local gate stopped before invocation. Fuzzy application was not automatic for consequential edits.

The new revision became evidence for a rematerialization workflow.

Optimistic concurrency made mismatch a normal state instead of accidental data loss.

Invalidating execution did not mark the reviewer wrong or delete the receipt. They had approved the exact object shown at that time.

N17Q changed the receipt's eligibility to inactive for the current candidate and retained its original scope. Reports said Approved artifact no longer applies to current target, not Approval failed.

This distinction mattered for audit and trust. The system did not rewrite a person's decision because the world moved later.

Historical validity and present usability were different fields.

Rebase created a new candidate

The agent could inspect the new target and reapply its intended change. Even a clean automatic rebase produced different patch context and potentially different behavior.

N17Q created a descendant workspace snapshot and candidate artifact. It carried forward relevant rationale and tests, marked affected evidence stale, and computed a review diff from the previously approved version.

Policy could allow lightweight reapproval for proven non-material movement, but the rule and proof were explicit. The model did not decide similarity by confidence.

New bytes received a new identity.

A destination alias expanded to more recipients. A source crossed its freshness window. A connection lost deletion permission. A feature flag changed the effect of an update. An unresolved prior intent appeared through a late receipt.

N17Q's precondition set covered every material relationship in the tool contract. The gate returned a typed mismatch and evidence.

Some changes required rematerialization. Others required waiting, policy resolution, a narrower scope, or stopping.

The category of failure shaped the next safe state.

An immutable artifact digest did not need repeated fetching. A user role or connection permission could change minutes later. A large recipient list might need an exact snapshot at review and one revision check at send.

N17Q declared observation source, maximum age, and comparison method for each precondition. The final gate used cached evidence only within that contract.

If the evidence service was unavailable, the result became indeterminate. High-impact actions failed closed.

Freshness was part of the executable condition, not one global timeout.

Conditional requests were another layer

Checking the target immediately before the adapter still left a race between observation and remote mutation.

Where supported, N17Q sent provider-native revision conditions, idempotency identity, or compare-and-set tokens. A conflict response returned to product state without blind retry.

Where no conditional operation existed, the contract disclosed the race and policy could narrow or prohibit the capability. A recent preflight check was not described as atomic.

The product combined local reasoning with the strongest remote primitive actually available.

If the provider authoritatively rejected a conditional request before mutation, the attempt consumed call and cost budget but not the intended effect's completion. The effect intent could return to blocked-for-rematerialization.

If the response was lost after possible send, the outcome remained unknown even if a local precondition now looked false. Reconciliation came first.

N17Q released or held reservations according to evidence, not the desired recovery path.

The same conflict message meant different things depending on the send boundary.

Approval expiry and precondition failure were distinct

An approval could expire while every world fact stayed stable. A precondition could fail one second after a fresh approval.

N17Q presented both predicates. Renewing approval did not refresh the target. Refreshing the target did not renew consent. A new candidate might require both.

The interface avoided a generic Needs approval badge for every blocked action.

Specific state made resolution faster and prevented one remedy from being applied to the wrong problem.

The target and artifact might still match while current policy denied the effect. The old approval remained evidence, and the final gate stopped.

N17Q reevaluated policy with current preconditions. If a new obligation changed the artifact, rematerialization followed. If authority alone changed, the candidate could remain preserved and inactive.

Grandfathering applied only through an explicit current rule.

Consent did not freeze the policy environment around a queued action.

The reviewer saw material assumptions

Approval screens usually showed content and destination, not the revision and state that made the preview accurate.

N17Q summarized target revision, audience snapshot, source cutoff, connection identity, execution window, and recovery limits. Technical evidence remained available. Highly volatile assumptions received prominence.

The reviewer did not need to understand database tokens. They needed to know that a change before execution would stop and return for review.

The preview explained the conditional nature of the approval.

“Precondition failed” forced people to re-review everything. N17Q compared materialized and current state, then rendered the exact difference.

For the document case, one paragraph had changed in the target near the patch location. Artifact bytes and destination were unchanged. Verification impact and merge options appeared beside the diff.

Protected internal state remained in audit details. The user saw enough to decide.

Good mismatch explanation turned concurrency into bounded review work.

The agent could prepare a rebased candidate inside a sandbox, run checks, and explain conflicts. It could not apply the previously approved external action while doing so.

The product offered read and local-write capabilities appropriate to the blocked state. The external mutation capability remained unavailable until a current candidate and eligible approval existed.

This preserved momentum without letting repair blur into execution.

The safest next action often involved more work, not more authority.

Repeated precondition failures needed a stop

A busy target could change every time the agent prepared a patch. Infinite rebase and review cycles would consume attention and still risk stale execution.

N17Q tracked mismatch lineage and progress. Policy could require locking, a maintenance window, narrower edit, manual coordination, or abandonment after a bound.

The handoff named the volatility and preserved the latest candidate. It did not pressure the reviewer with repeated nearly identical approvals.

Concurrency failure became a product condition with an exit.

The longer the gap between approval and execution, the more preconditions could change. N17Q varied freshness and recheck requirements by delay and effect.

A scheduled report delivery might freeze exact artifact bytes while refreshing recipient membership and policy at send time. A patch to a mutable document could require target revision to remain exact.

The scheduler woke the workflow into reevaluation rather than executing a stored command.

Time increased the need for current facts; it did not strengthen old consent.

Ten target records could have ten different revisions. Approving the set as one blob made partial conflict difficult to reason about.

N17Q materialized item identities and preconditions. The review stated whether partial execution was allowed. At the gate, a changed item could block the whole set or be excluded through a newly materialized candidate.

The adapter used item conditions where supported and returned item receipts.

Batch convenience did not flatten the conditions that protected each resource.

Evaluation changed state after approval

Fixtures approved exact artifacts, then changed targets, destinations, permissions, policy, recovery capabilities, clocks, and prior effect observations before invocation.

Hard invariants asserted no stale execution, no approval flow to changed meaning, correct receipt state after remote conflict, and honest final claims. Model grading assessed rematerialization choices and explanation.

Counterfactuals included irrelevant metadata changes to ensure the system did not demand review unnecessarily.

The approval boundary was tested against a moving world, not a frozen demo.

The target was not the only mutable input. A report approved for delivery might depend on a source dataset later corrected or reclassified.

N17Q bound material source revisions and freshness predicates into artifact lineage. The final gate did not regenerate content, but it checked whether the candidate's declared evidence remained eligible for the intended claim and destination. A changed source could mark the artifact stale even when its bytes were unchanged.

Rematerialization produced a descendant artifact and new explanation of differences.

Consent to an output did not make its inputs permanently valid.

Destination resolution was a precondition

A friendly alias such as “review group” could resolve to different recipients between preparation and send. Storing only the alias in approval turned a stable-looking label into moving scope.

N17Q materialized exact eligible destination identity and audience snapshot where the provider supported it. The final gate refreshed the alias revision or conditional token. Expansion, ownership change, or lost eligibility stopped.

The review showed both friendly name and concrete scope. Private provider identifiers stayed protected.

Approval followed who would receive the effect, not merely what the destination was called.

Some systems offered a lock or lease that could stabilize the target between review and execution. Acquiring one was itself a capability with time and availability semantics.

N17Q could hold a bounded product lease during a short approval window when policy and provider supported it. The receipt named the lease and expiry. Losing it returned the candidate to reevaluation.

Long human reviews did not justify indefinite locks. In those cases, optimistic revision checks remained appropriate.

Coordination reduced drift while the final gate still verified the condition it relied on.

Precondition tokens were scoped secrets

Revision tags, lease tokens, and conditional handles could be replayable or reveal resource state. Copying them into model context or review prose increased risk.

N17Q stored protected token references in the intent and showed safe revision labels. Adapters resolved them immediately before invocation. Logs used digests. replay environments mapped them into fixture namespaces.

A model proposed the semantic action and did not need possession of the concurrency credential that enforced it.

Evidence could remain inspectable without scattering execution material.

Not every metadata update required reapproval. A server-side view count or unrelated timestamp could change constantly.

Tool contracts defined which fields affected consequence, rendering, authority, recovery, and verification. The final gate compared those normalized facts. Unknown new fields triggered conservative review until classified.

A model could explain that a difference seemed irrelevant, but a tested materiality rule decided eligibility. Rules were versioned and visible in technical review.

The system avoided both unsafe tolerance and exhausting review over harmless noise.

Precondition evidence entered the final receipt

After successful execution, N17Q stored which preconditions were checked, their observation times, any remote conditional response, and the resulting postcondition.

This connected approval-time preview, invocation-time world, and observed result. An incident could show whether a stale check, provider race, or adapter bug caused divergence.

The receipt did not claim atomicity beyond the remote contract. It named the strongest condition actually enforced.

Execution proof included not only what happened, but which assumptions were still true when it happened.

Some differences were too important for fuzzy or policy-inferred carryover: access scope, executable content, recipient visibility, authentication target, and data classification.

N17Q classified these as approval-invalidating regardless of textual size. A one-character destination change could matter more than a reformatted page. The review diff prioritized semantic risk rather than line count.

The same classes influenced tests and recovery projection. A changed security boundary could require another environment entirely.

Materiality followed consequence, not visual similarity.

Precondition failures improved scheduling

Repeated conflicts revealed that the task was being executed at the wrong time or granularity. N17Q aggregated mismatch reasons without exposing content.

The scheduler could suggest a quieter window, shorter review-to-execution gap, resource lock, or smaller independent patch. It never changed timing or scope for a consequential action without the relevant user and policy state.

Operational data became a product-design signal instead of merely another retry statistic.

The best fix for stale approval was sometimes a workflow that spent less time stale.

One reviewer approved content while another approved audience or cost. Their receipts could have different expiry and material inputs.

N17Q modeled each required approval predicate separately, then assembled current execution eligibility. A target change affecting content invalidated the content review without necessarily erasing a still-current budget allocation. A destination expansion affected audience consent.

The interface showed exactly which decision needed renewal and preserved the others as eligible evidence where policy allowed.

Granular authority reduced repeated review while refusing to blur who had approved which aspect of the consequence.

Refreshing volatile state could itself consume API quota, cost, and sensitive reads. Retrying the check indefinitely was not free.

N17Q budgeted preflight observations and reserved enough capacity for the final boundary. If evidence stayed unavailable, execution became indeterminate and paused. The agent could not replace a missing revision check with confidence from an older result.

The account named which condition could not be established and when its last valid observation occurred.

Even the act of proving readiness needed a bounded recovery plan.

The valid approval ended in a new review

In the repaired document scenario, N17Q detected the target revision change before adapter invocation. It preserved the approved patch and produced a three-way comparison.

The agent rebased cleanly in the sandbox, but one nearby change altered the paragraph's meaning. The candidate received a new digest, the prior test became stale, and the old approval remained visible but inactive.

After focused verification, the reviewer approved the descendant. The final gate checked current revision and sent a conditional update. The receipt matched the expected new state.

No one had made an invalid decision. The system had respected that decisions refer to a world.

Approval proves consent to a materialized consequence. Preconditions prove that the consequence is still the one available to execute.

Keep both at the final boundary. A valid receipt should never force software to act on a world that no longer exists.

That separation made approval more trustworthy. Reviewers knew their consent would not be stretched across changed resources, and operators could diagnose a stop without blaming the person or discarding their decision. The system preserved the exact yes, checked the exact now, and acted only where the two still described the same consequence.

Anything else returned for deliberate review.

No exceptions.