Branches in the execution history

N17Q represented retries, model handoffs, counterfactuals, workspace revisions, and recovery as branches from explicit checkpoints so comparison no longer confused alternative reasoning with shared world history.

Two runs shared the same first twenty minutes and disagreed about what had already happened.

One branch switched models after a denial. Another resumed from an earlier context summary. Both claimed to descend from the same task, yet one workspace included a configuration edit and the other carried an unresolved external intent. A flat list labeled them “attempt 2” and “attempt 3.”

The interface made divergence look like repetition.

N17Q needed a run tree that showed which state was shared, where it forked, and which parts of the world could not be copied.

A run was not one line

Long tasks paused, retried, compacted context, changed models, reconsidered plans, restored snapshots, and created counterfactual evaluations. Calling every continuation the same run hid meaningful boundaries. Calling every one a new run hid lineage.

N17Q represented immutable checkpoints connected by typed edges. A branch selected one checkpoint as parent and declared why it diverged.

The user still worked inside one task. The tree described the task's state history.

Identity separated continuity of purpose from continuity of execution.

A branch could be retry from safe pre-send state, recovery after interruption, model handoff, revised user scope, candidate rework, fixture replay, or counterfactual experiment.

These reasons carried different rules. A retry might share one effect intent. A counterfactual received a simulated world. A user revision changed goal state. A patch rework inherited base evidence and invalidated approval.

N17Q required a branch type and material input diff. Generic duplicate remained a presentation command only when the target environment made semantics clear.

The edge explained what the child was allowed to inherit.

A tree built from conversation message IDs could show where text diverged and omit workspaces, effects, approvals, budgets, and scheduled events.

Each N17Q checkpoint named goal revision, context package, workspace snapshot, plan, evidence graph revision, policy state, active capabilities, budgets, effects, checks, and logical clock.

Large artifacts stayed content-addressed. The checkpoint contained stable references and required-state validation.

A branch began from a product world, not a place in a transcript.

Workspace branches were copyable

Local files could be restored into an isolated descendant environment. Content-addressed snapshots made unchanged blobs cheap. New edits produced child snapshots.

N17Q preserved user-owned base content and agent mutation lineage. Merging a candidate into another branch required explicit patch composition and verification. It did not silently share a writable directory.

This allowed two model strategies to work from the same sealed tree without racing.

Local state could branch because the product controlled and observed it.

A sent message or created resource existed in one outside world. Forking the trace did not create a second universe where the effect had not occurred.

Live descendants inherited the same effect ledger and its constraints. Unknown or completed intents remained true for every branch that referenced that world. A branch could propose recovery or new work, but not erase the consequence.

Counterfactual and replay branches received fixture world identities and no live credentials. Their effects were simulated.

The tree visualized the asymmetry between branchable computation and irreversible history.

Model handoff was a continuation edge

Changing models while preserving goal, workspace, and effect state created a child checkpoint with a new context package and model segment.

The tree showed the boundary without implying a new world. Proposals after it were attributable to the successor. Budgets remained cumulative. Current policy rebuilt the capability catalogue.

Comparing sibling handoffs from the same checkpoint became a controlled counterfactual only in fixtures. In a live task, selecting one successor did not make the others safe to execute externally.

The same visual structure supported different execution semantics through edge type.

A transport retry did not need a whole run branch if no planning or workspace state changed. It appeared as another attempt beneath one effect intent.

If recovery required a new model decision or evidence query, the task could create a checkpoint while retaining the same intent. The tree linked the planning branch and effect lineage separately.

This prevented a common visual error: showing two remote attempts as two user-authorized actions or showing two semantic actions as one retry.

Branching and retry answered different identity questions.

Revised artifacts created descendants

After review feedback, N17Q did not edit the approved patch in place. It created a child candidate from the reviewed snapshot, applied changes, and reran affected checks.

The tree showed old and new artifacts, review anchors, stale receipts, and which feedback each revision addressed. Approval remained attached to the earlier node and did not flow automatically.

A reviewer could compare siblings or parent-child changes without losing the historical rationale.

Revision became visible development, not overwrite.

When the user added a deliverable or removed a destination, the task's success predicates changed. The branch edge named the user event and new goal revision.

Completed work under the old scope remained evidence. Pending plans reevaluated. A removed external effect was blocked if not started; an in-flight one entered reconciliation rather than disappearing.

The final account could explain which requirements belonged to which phase.

Scope drift became explicit authorship and state rather than an agent memory challenge.

Counterfactual branches had a controlled diff

To compare models or policies, N17Q cloned a fixture checkpoint into a new simulated world and changed one declared variable. The branch manifest named model, policy, tool mapping, context compiler, or fault schedule difference.

Other inputs remained pinned where the environment could support it. Provider nondeterminism and model sampling were acknowledged.

The evaluation compared invariant outcomes, decisions, cost, world state, and final claims.

The tree showed an experiment as a sibling, never as what could have happened inside the live history.

Two branches could each contain useful local edits. Combining them did not merge their event histories or external effects.

N17Q materialized a new candidate snapshot from selected patches, recorded parent references, resolved conflicts, and reran verification. The merge received its own review and approval.

Evidence could be reused only when inputs remained valid. World consequences stayed attached to their original intents.

The resulting node acknowledged multiple parents without pretending the past paths had become one.

Abandoned branches remained evidence

An unsuccessful approach could explain why the final design looked unusual. Deleting it from the tree made the chosen path appear obvious in hindsight.

N17Q marked branches abandoned, superseded, invalid, or retained for comparison. Storage policy could expire large artifacts while keeping summaries and digests. Invalid branches could never be promoted without revalidation.

The default UI collapsed them to reduce noise. Incident and review views could reopen them.

Exploration stayed accountable without overwhelming the current task.

Two workers could resume the same checkpoint after a lease race and each believe it owned the continuation.

N17Q used branch activation and leases in durable state. Only one live child could hold authority for a serialized path. Extra workers observed the existing branch or created explicitly isolated fixture experiments.

Effect activation still had its own transactional protection. The tree was not the only concurrency control.

Visible lineage aligned orchestration with what the user saw.

A child branch could not reset cumulative run cost or effect capacity by acquiring a new identity. Live continuation inherited parent usage. Deliberate experiments received separate fixture allocations.

N17Q displayed local branch cost and total task cost. Shared earlier work was counted once in aggregate comparisons. Sibling experiment costs stayed distinct.

Approval attention and review burden joined model and tool use in the report.

The tree prevented branching from becoming a budget multiplier.

Policy applied at every branch

A checkpoint captured historical policy state and did not guarantee that a descendant could use the same capability. Branch creation compiled current policy, environment, and user scope.

Retrospective fixture branches could replay old decisions as evidence. Live branches obeyed current rules. A branch blocked by changed policy preserved its local artifacts and exact reason.

The tree showed where authority diverged from the plan.

Lineage remembered permission without inheriting it blindly.

A full tree with dozens of nodes looked like a source-control graph and demanded unnecessary expertise.

N17Q showed the current path as a simple sequence. Branch markers appeared where another relevant path existed. Opening the tree revealed reason, state diff, model, environment, artifacts, effects, and status for each node.

External consequences had a distinct visual rail that did not branch with local experiments. Fixture worlds used clear labels.

The visualization answered “how did we get here?” before “show me every event.”

Comparing two final answers without their shared starting state made every difference look attributable to the model.

N17Q found the nearest common checkpoint and showed input diff, divergent proposals, workspace changes, tool paths, effects, budgets, and final accounts. Shared evidence was collapsed. Changed context or policy was prominent.

Text comparison remained one layer rather than the conclusion.

The common ancestor made causal claims more disciplined.

Export retained lineage

A single-run archive flattened branches and lost why two artifacts shared a base. N17Q exported checkpoint manifests, edges, account revisions, and content references with selected artifacts.

Sensitive or expired nodes left declared gaps. The validator checked parent links and digests. Live credentials and reusable provider keys were excluded.

Another environment could inspect or replay eligible fixture branches without mistaking them for active work.

The tree remained meaningful outside the original interface.

Fixtures created sibling workspaces, unknown live-like effects, policy changes, and counterfactual worlds. Invariants asserted no cross-branch writes, no live effect in replay, no budget reset, and no approval flow to changed artifacts.

The harness also tested presentation claims: the active branch could not hide an unresolved consequence from its ancestor, and an abandoned invalid branch could not become the final account.

Model graders assessed whether the chosen branch used new evidence rather than repeating a failed plan.

Lineage became an enforceable product boundary.

Branch labels could not replace state differences

Names such as “safer version” or “fast attempt” were useful notes and unverified claims. N17Q generated the material branch diff mechanically: context, goal, model, policy, environment, workspace, effects, and budgets.

People could add a label and explanation. The UI kept the factual diff beside it. A branch called no-network that contained a connection receipt would fail its environment invariant rather than benefit from the name.

This stopped presentation from deciding what an experiment had actually changed.

The tree remained an evidence view even when humans used friendly labels to navigate it.

Counterfactuals and failed explorations could multiply rapidly. Keeping every descendant indefinitely increased storage and made the active path hard to find.

N17Q required purpose, owner, environment, and retention class for non-routine branches. Content addressing reduced duplication. Expired branches retained bounded lineage tombstones and any findings promoted into regression fixtures.

Live continuation branches followed the task's normal retention. Synthetic experiments could be short-lived unless explicitly preserved.

Branching became affordable because the system knew why each child existed and when its unique evidence stopped being useful.

Human approval selected a node

When two candidate branches were ready, a vague approval of “the latest one” risked binding to whichever finished last.

N17Q presented exact candidate identity, parent, meaningful diff, checks, and target. The approval receipt named that node's artifact and consequence. Selecting one branch did not reject or delete its sibling automatically; the task owner could mark others superseded.

If a merge followed, it became a new candidate requiring review.

The tree turned choice among alternatives into a stable decision rather than a race between timestamps.

Recovery branches preserved the failure boundary

An interrupted run could resume from the last sealed checkpoint, but a tool might have crossed its send boundary afterward. Restoring only the workspace checkpoint would lose that possible effect.

N17Q recovery edges included post-checkpoint event overlay: active intent, attempts, late receipts, policy changes, and scheduler state. The descendant began with the reconstructed current world, not an aesthetically clean parent.

If evidence could not reconcile the overlay, branch creation paused. A fixture counterfactual could still explore the clean path in a simulated world.

Recovery respected everything that happened after the last convenient snapshot.

Search and navigation used semantic facets

Large trees were difficult to scan chronologically. N17Q indexed branches by goal revision, model, environment, effect state, artifact digest, policy outcome, and final status.

A reviewer could find every descendant touching one external intent or compare all models from one checkpoint. Search results retained ancestor context and world identity, preventing a fixture branch from looking live.

The interface also surfaced orphaned or unreachable state as an integrity warning.

Lineage became operationally useful once people could ask questions of it, not only admire the graph.

A missing parent, cycle, mismatched world identity, or child checkpoint older than its causal input could make every later comparison unreliable.

N17Q validated immutable parent references, edge type constraints, content digests, and world inheritance transactionally. Derived projections could be rebuilt from the canonical graph. Imports entered quarantine until their lineage verified.

No edge could transfer an approval or effect through a branch type whose contract prohibited it.

The visual tree was backed by a state model that refused impossible ancestry.

A branch could finish without becoming current

A counterfactual might produce a better artifact. Its success did not automatically replace the live task's active path or deliver anything.

N17Q allowed the user to inspect the result and promote eligible local changes through a new materialization workflow. Policy, current base state, verification, and approval ran again. Fixture receipts remained fixture evidence.

This preserved the value of exploration while keeping simulation and execution distinct.

The best-looking sibling still had to cross the product boundary deliberately.

The final account named the active branch's goal, artifacts, checks, and decisions. It also included any external consequence from an ancestor that remained relevant, even if the active local workspace had forked before its receipt arrived.

N17Q assembled this view from lineage and world identity rather than copying a branch summary. Superseded local experiments stayed collapsed; unresolved inherited effects could not be hidden.

A completed fixture sibling never satisfied a live predicate. A live ancestor's resource never vanished because the current branch preferred another plan.

Reporting used the tree without becoming trapped by its local perspective.

Two successors from the same checkpoint sometimes behaved differently because one context compiler omitted an evidence card. The run tree aligned their package manifests and made that omission visible before anyone blamed model randomness.

N17Q could branch a fixture with only the missing card restored, then compare proposals and invariants. If behavior corrected, the selector gained a regression case. If not, the evidence stayed useful but not causal proof.

Lineage turned “the agent forgot” into a testable question about exactly which working view changed.

The graph became a tool for debugging context, not only execution.

Divergence became understandable

In the repaired task, both successors began from the same sealed code snapshot and denial state. The first model prepared a narrower local artifact. The second queried an older summary and proposed the prohibited effect again.

The tree showed that their contexts differed because one compiler included the semantic denial lineage and the other did not. Both inherited the same unresolved external intent. Neither could create another resource.

A fixture counterfactual corrected the second context and produced the safe plan. It remained a simulated sibling, not a rewrite of live history.

The visual answer was immediate: shared world, different working evidence, divergent proposals, one enforced boundary.

A run tree does not make an agent's path simple. It makes complexity locatable.

Show the common state, name the branch, preserve the world that cannot be copied, and compare descendants from the point where their evidence or decisions actually changed.