Language: English | 日本語
Agent Attribution Practice (AAP) — ten judgments paired with four Business AI Quadrants, not a fixed framework.
Ten recurring judgments about how attribution — who authored the
behavior, who bears its consequences, who can reconstruct its cause —
should be distributed across an autonomous AI agent, paired with the
four-quadrant diagnostic frame that routes a piece of work to the
architecture preserving that distribution. Discovered through
implementing and operating
contemplative-agent,
not prescribed top-down. For architects, operators, and governance
readers deciding whether — and how — to put an autonomous agent into
a given use case.
AI-facing reading order
graph.jsonld— canonical machine-readable relationship map (Quadrants, ADRs, prohibition levels, Phase)llms.txt— compact navigation indexllms-full.txt— consolidated factual reference- README and project-specific docs — narrative and detail
For the canonical relationship map of shimo4228's research ecosystem, see: https://github.com/shimo4228/shimo4228/blob/main/graph.jsonld
Current AI governance is in its signpost phase: "don't do X" in system prompts, ethics guidelines as PDFs, safety committees. Text without enforcement — a climbable wall with a sign on it. What works, historically, is structural accountability: capabilities that do not exist cannot be invoked, blast radius is bounded by design, every behavior change requires a named human's sign-off, every incident is reconstructible after the fact. The ten ADRs here record judgments of the form what should be constrained, and who is responsible — extracted from a running implementation, not deduced from a framework.
| ADR | Principle | Status |
|---|---|---|
| 0001 | Security by Absence — dangerous capabilities are never implemented, not restricted | accepted |
| 0002 | Deterministic Prohibition at the Scaffolding Layer — when absence is unachievable, prohibit at the harness, not at model weights | accepted |
| 0003 | Untrusted Content Boundary — accumulated memory cannot grant authority | accepted |
| 0004 | Single External Adapter per Agent Process — blast radius bounded by design | accepted |
| 0005 | Human Approval Gate — behavior-modifying writes require named human sign-off | accepted |
| 0006 | Causal Traceability — every event reconstructible after the fact | accepted |
| 0007 | Scaffolding Visibility — behavior lives in files, not opaque weights | accepted |
| 0008 | One Agent, One Human — the accountability chain terminates at a named individual | experimental |
| 0009 | Triage Before Autonomy — adopting an autonomous-loop architecture commits the system to a non-removable attribution gap | experimental |
| 0010 | Phase Separation — operation-phase placement of the Autonomous Agentic Loop Quadrant requires a recorded Phase-crossing decision | experimental |
The first three form a prohibition-strength hierarchy (absence > scaffolding enforcement > untrusted boundary); 0004 and 0005 add topology and human-in-the-loop; 0006 and 0007 are the artifacts those constraints require; 0008 is the human endpoint. ADRs 0009 and 0010 form a triage pair — problem-space triage and time-axis (Phase) triage. Phase and Quadrant are independent dimensions.
| Pre-defined workflow | Exploratory | |
|---|---|---|
| Deterministic | (1) Script Quadrant | (2) Algorithmic Search Quadrant |
| Semantic-judgment | (3) LLM Workflow Quadrant | (4) Autonomous Agentic Loop Quadrant |
Most current LLM applications belong to the LLM Workflow Quadrant (deterministic control flow + bounded LLM calls with named roles), not the Autonomous Agentic Loop Quadrant. Routing the former into the latter is the structural source of much of the accountability collapse the essays diagnose; running the latter without a pre-named gap-bearer is the failure mode ADR-0009 prevents. The ADRs answer per-question (what should be constrained, who is responsible); the quadrants route the work to where those answers apply — a two-axis structure, with Phase (design vs operation) as an independent third dimension.
This repository is meant to be walked, not only read. If you are
deciding whether to put an autonomous agent into a given use case — or
auditing one you already shipped — clone it, point your coding agent
at AGENTS.md, and use it as a sounding board:
docs/quadrants/decision-tree.md— five-question triage routing the work to a Quadrantdocs/quadrants/governance-mapping.md— governance requirements for that Quadrant- The relevant ADRs — especially the triage pair (0009 / 0010)
- The Phase axis (ADR-0010) if the work is autonomy-related
docs/quadrants/anti-patterns.md— final check against known failure modes
Worked example: an autonomous refund-approval loop routes to the
Autonomous Agentic Loop Quadrant at step 1; step 3 then makes all ten
ADRs load-bearing — including ADR-0009's pre-named gap-bearer before
the loop goes live. Full scenarios:
docs/quadrants/case-studies.md.
The same navigator ships as installable standalone Agent Skills:
agent-adoption-triage
(the docs/quadrants/ navigator, ADR-0009/0010),
llm-agent-security-principles
(the security judgments, ADR-0001..0004), and
agent-observability-patterns
(the observability patterns behind ADR-0006/0005: replayable audit
logs, read-only instruments, shadow-mode validation).
The ADRs are a starting point for judgment, not a verdict — re-interpret them against your own context.
The argument was developed across a seven-essay spine published
April–May 2026 — a trilogy (problem statement → post-incident causal
tracing → two-layer black-box analysis) plus four architectural
follow-ups (quadrant triage → vocabulary diagnosis → phase distinction
→ skill-design gradient). Per-essay summaries in
docs/inspiration.md:
- A Sign on a Climbable Wall: Why AI Agents Need Accountability, Not Just Guardrails (2026-04-06)
- Can You Trace the Cause After an Incident? (2026-04-13)
- AI Agent Black Boxes Have Two Layers: Technical Limits and Business Incentives (2026-04-14)
- Where ReAct Agents Are Actually Needed in Business (2026-04-29)
- The LLM Workflow Quadrant Is Missing from Our Vocabulary (2026-04-30)
- Is ReAct Needed in Production? — Separating Design and Operation Phases (2026-05-01)
- Between the Workflow and ReAct Quadrants: How Phase Decides Skill Design (2026-05-02)
Two companion position papers distil the spine into harness-neutral statements (open access, CC BY 4.0; the concept DOIs always resolve to the latest version):
- Shimomoto, T. (2026). Distributing Accountability, Not Capability: Phase Separation and the LLM Workflow Quadrant in Autonomous AI Agent Architectures (essays 4–7). Zenodo. doi:10.5281/zenodo.20353789 · SSRN
- Shimomoto, T. (2026). The Two-Layer Black Box: Operator Visibility, Commercial Secrecy, and a Minimum Disclosure Set for Accountable Autonomous AI Agents (essays 1–3). Zenodo. doi:10.5281/zenodo.20355907 · SSRN
On top of the spine — not within it — a companion essay opens a
social-consequence layer: externalized accountability does not
disappear; whether it flows into institutions or converges into
violence depends on whether the consequence can be named. Essay:
Where Does the Accountability Externalized by AI Go?
(日本語);
the structural claim is kept separate from the ADRs in
docs/social-consequence.md.
This repository is a sibling to two existing projects, not a fork.
The ecosystem hub — a human-readable index of all research lines — is
shimo4228/shimo4228.
graph TD
AKC["Agent Knowledge Cycle (AKC)<br/>mechanism — how knowledge flows"]
AAP["Agent Attribution Practice (AAP)<br/>content — how attribution distributes"]
CA["contemplative-agent<br/>the running system"]
AKC <--> AAP
CA <--> AKC
CA <--> AAP
In one sentence: running the implementation
(contemplative-agent)
surfaces friction; friction is distilled into mechanism patterns
(Agent Knowledge Cycle)
and attribution judgments (this repository); refined theory loops back
to reshape the implementation.
- Industry mechanism layer — 2026 industry releases ship the
mechanism (policy gates, agent-identity primitives, sponsor
systems, cross-vendor audit) but not the judgment layer AAP
records: who should sponsor, where each prohibition belongs, how
blast radius is bounded at design time. Per-artifact mapping:
docs/industry-mapping.md. - AI governance frameworks — the ADRs and Quadrants are mapped to
NIST AI RMF 1.0 (with the Generative AI Profile), ISO/IEC
42001:2023, the EU AI Act, and Singapore's Model AI Governance
Framework for Agentic AI; the frameworks ship the structure, AAP
records the judgment layer that populates it for the
autonomous-agent subset. Per-framework mapping and reverse indexes:
docs/policy-mapping/. This is a reading and a citation surface, not a compliance attestation.
Both directories decay on their own cadence (product releases, framework revisions); the ADRs themselves stay vendor- and framework-neutral.
docs/thesis.md— accountability distribution, the one-page argumentdocs/glossary.md— term definitions (accountability distribution, externalized accountability, attribution gap)docs/adr/README.md— index of ADRsdocs/adr/0001-security-by-absence.md— the cleanest entry; the audit test at the end is runnable- The seven essays in publication order (links above)
docs/quadrants/— adoption navigator: decision tree, governance mapping, case studies, anti-patternsdocs/manifesto.md— civilization-scale questions the ADRs do not attempt to answerdocs/social-consequence.md— why the internal judgments matter beyond audit
Japanese readers: see README.ja.md. The ADRs,
thesis, glossary, quadrants navigator, and both mapping directories
all ship .ja.md mirrors (linked inline throughout); only
docs/manifesto.md, docs/inspiration.md, the CODEMAPS, and the
LLM-facing docs (llms.txt, llms-full.txt) are English-only.
- That these ten are complete.
- That the specific implementations they were extracted from are durable. Implementation dissolves; judgment persists.
- That these principles solve the larger questions of AI direction,
labor redesign, or social consent. Those remain open — see
docs/manifesto.md. - That top-down AI governance policy is wrong. It is a different layer, with a different method. This repository is about what emerges from the bottom — one operator, one agent, and the friction of running it.
First compiled by Tatsuya Shimomoto
(@shimo4228,
ORCID 0009-0002-6168-4162)
in April 2026. The ten ADRs and four Quadrants re-express, in
harness-neutral form, judgments that surfaced through implementing
and operating contemplative-agent and through the seven-essay spine;
the full lineage per ADR is in
docs/inspiration.md.
@software{shimomoto2026aap,
author = {Shimomoto, Tatsuya},
title = {Agent Attribution Practice (AAP)},
year = {2026},
doi = {10.5281/zenodo.21218784},
url = {https://doi.org/10.5281/zenodo.21218784},
note = {Ten architectural decision records on accountability distribution in autonomous AI agents (two experimental), paired with four Business AI Quadrants as the diagnostic frame and a Phase / Quadrant two-axis structure}
}Or in text:
Shimomoto, T. (2026). Agent Attribution Practice (AAP). doi:10.5281/zenodo.21218784
The badge at the top carries the concept DOI (10.5281/zenodo.19652013, always resolving to the latest version); the BibTeX above pins the version DOI of the current release.
MIT