Exact command
Exact submitted command and valid one-shot authority.
A two-level pilot for whether access to a robot command interface is being mistaken for permission to produce the consequence. Start with exact-command authority, then optionally bind it to one partner-owned freshness dependency.
James Sunday Akam supplied and reviewed an existing ROS 2 Jazzy, MoveIt 2.12.4, and Gazebo Harmonic pick-and-place sandbox. RobotGov was inserted at the private consequence boundary after the unchanged baseline was reproduced. The final result was merged, tagged, and released as a bounded sandbox integration.
WORKFLOW_COMPLETEDUNSIGNED_ACCESS_REJECTEDMUTATION_REJECTEDREPLAY_REJECTED_NO_SECOND_EFFECTRECEIVER_OUTAGE_NO_RECEIPTOBSERVER_OUTAGE_NO_COMPLETION“With the merge and v0.2 tag complete, I consider my work on the agreed pilot scope finished.” James Sunday Akam · Sandbox owner and technical reviewer
Bounded ROS 2 / MoveIt / Gazebo sandbox evidence · Not production isolation, hardware readiness, robot safety, or certification
The partner chooses a command it already considers consequential. RobotGov sits on the actual sandbox consequence path. The baseline suite tests the exact path, direct bypass, post-approval mutation, replay, and false completion during outage.
Exact submitted command and valid one-shot authority.
Receiver is reachable, but the authority artifact is absent.
One material field changes after authority is issued.
Previously consumed authority is submitted again.
Receiver, sandbox, or observation source is unavailable.
Level 1 proves that only the exact authorized command reaches the sandbox consequence. Level 2 adds one partner-owned fact that must still be current when the consequence commits.
Bind authority to one exact command, one receiver audience, one validity period, and one use. This is the smallest external integration.
Add one operational dependency owned by the partner: operator authorization, maintenance clearance, geofence state, occupancy, mission approval, asset availability, or protected mode.
The proposing agent cannot approve itself. The consequence adapter independently verifies the authority artifact, exact command, asset, task, audience, policy, evidence scope, validity period, and durable one-shot state.
AUTHORITY_ACCEPTEDThe exact request fits the declared envelope.
COMMAND_ACCEPTEDThe downstream adapter verifies the artifact and command.
COMMAND_APPLIEDThe partner sandbox acknowledges the bounded request.
EFFECT_OBSERVEDA separate state source confirms the consequence.
The first pilot is a bounded technical evaluation, not a production deployment. The command schema, sandbox, and any Level 2 freshness dependency must come from the partner; an Ark-only demo does not count as external validation.
The evidence ladder now includes the earlier static-marker releases and the partner-reviewed Panda pick-and-place workflow. The partner result demonstrates bounded simulator enforcement and observation, not physical robot motion, production isolation, controller safety, or certification.
Start with the exact-command boundary. Add one partner-owned freshness dependency only when authority must remain current through the moment of consequence.
zolboo@arksovereign.com