# Sentinels

A Sentinel is the Actor configuration that operationalizes Coherence. It has no inherent Authority. A binding grants observation and protective capabilities for named scopes, data, purposes, responses, and expiry.

## Scopes

One Sentinel runtime supports multiple scope records:

- **system** — enforce constitutional, safety, and platform/legal boundaries;
- **Realm** — assess governed norms and Realm-level patterns;
- **entity** — assess one Ally, Actor, or Avatar binding;
- **interaction** — assess a bounded Activity/session;
- **relationship** — assess continuing dynamics under participant Consent.

These scopes do not require five autonomous agents. Deploy separate processes only for isolation, jurisdiction, latency, or governance reasons.

## Runtime loop

1. Receive a typed Event and resolve subject/scope.
2. Verify observation Authority, Consent, purpose, visibility, and retention.
3. Minimize evidence and classify deterministic facts versus inferences.
4. Produce observations with method ceilings.
5. Update current state using the dimension's decay and evidence rules.
6. Resolve effective profiles/policies with field-level provenance.
7. Compute target distance, band drift, confidence, and boundary status.
8. Evaluate higher-order constraints before local targets.
9. Select the least-forceful permitted response.
10. Execute only if the response is within current Authority; otherwise propose or escalate.
11. Record inputs, policy/profile versions, reason, output, and appeal/recovery route.
12. Observe outcome and feed adjudicated results to calibration.

## Capability limits

A Sentinel MAY observe, measure, explain, recommend, apply reversible bounded AI/Actor modulation, preflight Actions, narrow scope, pause, deny, mediate, start an authorized repair workflow, and escalate.

A Sentinel MUST NOT widen Authority, grant tools or Connections, override Consent, invent evidence, secretly manipulate a Source, permanently sanction by itself, erase Records, approve its own exception, or release its own quarantine.

## Failure behavior

- Unknown profile/policy version: fail closed for consequential Actions; continue observation-only for low-risk interaction.
- Measurement unavailable: preserve original behavior unless a deterministic boundary requires pause.
- Conflicting equal-priority policy: pause affected Action and request accountable resolution.
- Event sink unavailable: deny non-idempotent consequential intervention until an auditable Record can be written.

