Six Fathoms
marque
A commission to act — scoped, time-bounded, and on the record.
Someone — or something — needs to run a statement against production. Today that is a Slack thread, a screen share, and a psql prompt with the whole schema behind it. Marque turns it into a reviewed, signed, expiring grant: you submit the statement, it is rehearsed in a transaction that never commits so the row count is measured rather than guessed, a human with the authority to say yes signs it — and only then, only that statement, only as that role, only inside that window, does it run.
That is also how you give an agent production access. An LLM acting for a person submits as itself, runs what is inside a scope it partly declares for its own task, and escalates everything else to its human — who approves in seconds, with the analysis in front of them. Never a credential. Never an approval. Never a shortcut through any check.
Status: M1, the walking skeleton, runs. 42 decision records are published, and
M1's steps execute against a real PostgreSQL. It has no signing, no grammar, no identity and no
fence, so every command but version refuses to start without an explicit
acknowledgement. Nothing here has run against a production database, and nothing should.
What it looks like
One statement, followed from the moment someone types it to the moment somebody reads the record months later — and then the paths you reach for at three in the morning: marking a request urgent, breaking glass, and working the queue of everything you have in flight. Step through it, or let it play.
Illustrative. This is the flow the decision records specify — not a recording of running software. Implementation has begun at the scaffolding milestone and none of this flow exists yet, so every transcript above is written from the records rather than captured from a terminal.
What a request looks like
An operator submits one or more statements against a named target and a named role, with a reason. The Leadsman reads them and reports what they touch, how many rows a rehearsal changed, and which past requests looked like this — advice, never a decision. An approver with authority over that target reviews, edits if they want to, and signs a marque with a validity window. The submitter runs it, once or up to a budget, within that window. The logbook keeps the statement, the analysis, the signature, and the result.
Agents, supervised rather than trusted
The usual way to give an agent production access is to hand it a credential and hope. Marque's answer is that an agent never holds one. It authenticates as itself, acts on behalf of a named human, and what it may do without asking anybody is an intersection of three scopes:
That third term exists nowhere else, and it is nearly free: an agent knows that this run only needs order 88213, so it says so and is held to it. An agent declaring a wide scope for a narrow task becomes visible before anything runs.
Anything outside is not refused — it is escalated. To that human first, always, and then to whoever policy additionally requires. The agent parks; a person answers; the work resumes. When it finally runs, the record is one sentence: the agent executed it, on Sam's behalf, authorised by Sam and the data on-call, affecting one row.
A model never creates authority here. It can compile a delegation you write in English — which you then read and sign — and it can route a request as conforming or referred, always inside a bound a human already signed, always referring on doubt. The worst a model error can do is fail to escalate something that was already in scope.
What it is for
Approval that expires
A marque carries a not-before, an expiry, and an execution budget. Standing access is a lease that has to be renewed, not a door left open.
EDR-0004 →The approver signs, not the server
The signature on a marque is the approver's own key. A compromised control plane cannot manufacture authority it was never given.
EDR-0005 →Delegation with a scope you can read
Object scope is proved statically; row scope is a transactional fence that aborts and tells you how many rows rather than silently narrowing your statement.
EDR-0007 →Write the delegation in English
"Sam can update settings on sandbox accounts, up to 100 rows." A model compiles
it; you read and sign the compilation; enforcement is deterministic from then on.
Escalation, not refusal
Out-of-scope work routes to a chain of named humans — an agent's own principal first. Each stage adds only the authority it holds, and a timeout never approves.
EDR-0019 →Routine work never queues
Standing orders are parameterised statements approved once, with per-parameter constraints. Support runs them all day without waking anybody.
EDR-0008 →A machine reads it first
Static analysis plus a rehearsed, rolled-back run supply the facts; a model writes the summary. It is advisory input to a human, and it can never approve.
EDR-0009 →Agents get scope, not credentials
An agent submits as itself for a named human, inside a scope it partly declares per task, and escalates the rest. It never holds a credential and can never approve.
EDR-0018 →One URL to configure a client
Point the CLI at a deployment and it discovers the issuers, audiences, targets and relays it needs. There is nothing else to set up.
EDR-0002 →Questions you can answer afterwards
The case for running this is mostly felt later — in an incident review, an audit, or the hour after something went wrong. These are the questions that are usually unanswerable, and what answers them here.
“Who changed this row, and who said they could?”
One query. The answer includes the statement text, the analysis the approver was actually looking at, and their signature over it.
EDR-0012 →“Was that the model, or the person?”
A column, not an investigation. Anything an agent did carries both names — the actor and the human it acted for — and a one-name record is rejected at write time.
EDR-0018 →“Did anyone know it was 412 rows?”
The rehearsed count is bound into what the approver signed, so what they were shown is provable after the fact rather than remembered.
EDR-0010 →“Did that apply, or not?”
Including the honest answer. An execution whose outcome could not be established is recorded
as indeterminate rather than guessed at in either direction.
“What can this tool actually reach?”
A short list of roles and their grants, in the database’s own vocabulary. A bug in Marque’s scope checker is contained by the role, not by Marque.
EDR-0006 →“Can we still work if Marque is down?”
A marque already issued keeps executing — the Pilot verifies it by computation, offline. The tool stays usable during the incidents it exists for.
EDR-0004 →