Open-source Runtime Authority

Your AI can act. Don't govern it with another black box.

Models are workers. Runtime is authority.

Models are becoming capable workers. Once they can operate tools, repositories, and systems, the hard question is no longer only whether they can perform the task.

Predator Result on the write-capable alpha: docs/NOTES.md bullet added, diff open, changes on an isolated sandbox branch, Mission sealed, acceptance unverified
Predator v3 — a real write Result on the isolated write-capable alpha. Diff, sealed Mission, acceptance state, and changes that stayed on an isolated workspace branch.

The problem

Who holds authority over execution?

What can the AI change? How far may it proceed? When must it stop? What evidence remains? Who accepts the result?

What can change?

Workers can draft plans and patches quickly. That does not make them trustworthy executors.

How far may it proceed?

Asking a model to be careful cannot revoke a write grant or prove a path stayed in scope.

Who accepts the result?

If it is not recorded, it is not runtime truth. Scrollback is not an audit trail.

Why Runtime Authority

What is Runtime Authority?

What the category is, and why AMOF exists.

Why Runtime Authority — conceptual explainer

How AMOF governs work

Intent becomes a Mission. A Run is one bounded execution.

The Target Set and write envelope declare the boundary before anything mutates. Preview and Promote stay human actions.

Runtime Authority

What the runtime owns

What the runtime owns

Runtime Authority

Owns Missions, policy, Evidence, stop authority, and release readiness

  • Plans
  • Enforces
  • Coordinates
  • Records
Workers propose. The runtime owns truth, policy, and stop.

Deep dive: Runtime Authority architecture — product concept page, not a personal blog.

AMOF in action

Private operator console

Predator v3 is Hotshot's private operator console. An isolated write-capable alpha is live. Not in the public OSS distribution; not a public login.

Predator v3 first contact: WRITE-ENABLED ALPHA card, no Project yet, bounded-write authority
01 — First contact
Create Project form with sandbox repository and declared writable roots
02 — Project
Project Repositories tab: bound public sandbox with writable roots listed
03 — Repositories
Assistant compiled a Mission packet from a plain-language docs intent
04 — Intent
Director handoff in progress: sending a governed write Run
05 — Governed Run
Governed write Run executing on the write-enabled alpha
06 — Running
Result R-001 with docs/NOTES.md diff open on an isolated sandbox branch
07 — Write executed
Files and evidence under the Result: changed docs/NOTES.md, Diff and evidence entries
08 — Evidence
Settled Result with Start a new Mission and Continue this Mission
09 — Continue Mission
Refused Makefile write outside declared roots with Widen writable roots control
10 — Boundary blocked
Project edit widening writable roots from docs to docs, src
11 — Widen roots
Second Run R-002 selected, write-scope approval required, Allow Reject Edit controls
12 — Needs You

01 — First contact

    Real screens from the isolated write-capable alpha (September 2026). Refused, blocked, and Needs-You states are part of the product — not hidden.

    Today

    What you can do today

    Public AMOF is the installable runtime. Predator stays private.

    Public AMOF

    Clone and install the open-source runtime and CLI (Apache-2.0), AMOF 3.4.0 (released). Run it on your own machine. It does not ship Predator.

    Predator v3

    Private operator console. Isolated write-capable alpha. Not a public login.

    Non-claims

    What AMOF is not

    Direction

    Validated direction, not shipped

    These are architectural findings. They are not product claims.

    One truth core, multiple shells

    AMOF owns Mission, Run, write authority, Evidence, acceptance, and receipts. Predator is one engineering projection. An executive shell is later — architecturally sound, not built.

    Human Understanding contract

    Ordering is shipped in Predator: understanding first, evidence underneath, raw execution last. Explicit understanding fields (purpose, approach, consequence) are a proposal.

    Standing Missions

    Durable responsibility across bounded cycles is a discovery. It is not shipped and is not claimed.

    AMOF LOG

    AMOF LOG — audio deep dives

    Season 2 Episode 1 is playable here. The episode page lives on hotshot.sk.

    Season 2 · Episode 1

    Token Physics and Autonomous Context Hygiene

    Season 2 of AMOF LOG opens on token physics and autonomous context hygiene: how autonomous AI engineering stays accountable, how context is assembled with provenance, and why cryptographic receipts matter. The episode covers context hygiene across follow-on Missions, durable synthesized state, and runtime economics — treating tokens as telemetry rather than a substitute for vendor-price accounting. This is an engineering deep dive, not a product launch.

    What the runtime can enforce

    Scopes, approvals, and Evidence

    Enforcement that connects

    Writable scopes

    Bounded paths and capability modes. Over-bound work fails closed.

    Approvals

    Human gates where mutation matters. Operators keep stop authority.

    Evidence

    Secret-safe receipts and run records. If unrecorded, not runtime truth.

    Runtime identity binds the loop Who ran what, under which grant, with which Evidence — replayable.
    Scope, approval, and Evidence must connect — or trust is theatre

    Architecture

    Workers propose. Runtime decides what is true.

    Models and tools are replaceable. They do not own grants.

    Who owns what? Runtime Authority is not an AI agent

    Runtime Authority

    System of record

    • Owns Missions and Runs
    • Owns policy and write grants
    • Owns coordination and stop
    • Owns Evidence and receipts
    • Owns release readiness

    Workers

    Replaceable cognition

    • Propose plans and patches
    • Execute bounded tool calls
    • Can be swapped under policy
    • Never own runtime truth
    • Never grant their own scope
    Runtime Authority owns truth and policy. Workers stay replaceable.

    Product proof

    Named surfaces. Honest maturity.

    Public OSS — AMOF 3.4.0

    AMOF 3.4.0 is released: usable public Write-Scope lifecycle — bounded_write recognised, Binding roots replace executor roots, out-of-scope writes blocked as scope_exceeded.

    Predator v3

    Private operator console. Isolated write-capable alpha.

    Evidence-first

    Receipts, run records, and runtime logs are first-class. Missing provider cost stays unknown — never fabricated.

    Next step

    Install the public runtime.

    Apache-2.0. Predator stays private.