Six Fathoms

marque

A commission to act — scoped, time-bounded, and on the record.


Someone — or something — needs to run a statement against production. Today that is a Slack thread, a screen share, and a psql prompt with the whole schema behind it. Marque turns it into a reviewed, signed, expiring grant: you submit the statement, it is rehearsed in a transaction that never commits so the row count is measured rather than guessed, a human with the authority to say yes signs it — and only then, only that statement, only as that role, only inside that window, does it run.

That is also how you give an agent production access. An LLM acting for a person submits as itself, runs what is inside a scope it partly declares for its own task, and escalates everything else to its human — who approves in seconds, with the analysis in front of them. Never a credential. Never an approval. Never a shortcut through any check.

Status: M1, the walking skeleton, runs. 42 decision records are published, and M1's steps execute against a real PostgreSQL. It has no signing, no grammar, no identity and no fence, so every command but version refuses to start without an explicit acknowledgement. Nothing here has run against a production database, and nothing should.

What it looks like

One statement, followed from the moment someone types it to the moment somebody reads the record months later — and then the paths you reach for at three in the morning: marking a request urgent, breaking glass, and working the queue of everything you have in flight. Step through it, or let it play.

marque — prod-primary Illustrative


    

Illustrative. This is the flow the decision records specify — not a recording of running software. Implementation has begun at the scaffolding milestone and none of this flow exists yet, so every transcript above is written from the records rather than captured from a terminal.

What a request looks like

1 submit→ 2 sound→ 3 review→ 4 sign→ 5 run→ 6 log

An operator submits one or more statements against a named target and a named role, with a reason. The Leadsman reads them and reports what they touch, how many rows a rehearsal changed, and which past requests looked like this — advice, never a decision. An approver with authority over that target reviews, edits if they want to, and signs a marque with a validity window. The submitter runs it, once or up to a budget, within that window. The logbook keeps the statement, the analysis, the signature, and the result.

Agents, supervised rather than trusted

The usual way to give an agent production access is to hand it a credential and hope. Marque's answer is that an agent never holds one. It authenticates as itself, acts on behalf of a named human, and what it may do without asking anybody is an intersection of three scopes:

∩ operator policy ∩ its human's delegation ∩ the scope it declared for this task

That third term exists nowhere else, and it is nearly free: an agent knows that this run only needs order 88213, so it says so and is held to it. An agent declaring a wide scope for a narrow task becomes visible before anything runs.

Anything outside is not refused — it is escalated. To that human first, always, and then to whoever policy additionally requires. The agent parks; a person answers; the work resumes. When it finally runs, the record is one sentence: the agent executed it, on Sam's behalf, authorised by Sam and the data on-call, affecting one row.

A model never creates authority here. It can compile a delegation you write in English — which you then read and sign — and it can route a request as conforming or referred, always inside a bound a human already signed, always referring on doubt. The worst a model error can do is fail to escalate something that was already in scope.

What it is for

Approval that expires

A marque carries a not-before, an expiry, and an execution budget. Standing access is a lease that has to be renewed, not a door left open.

EDR-0004 →

The approver signs, not the server

The signature on a marque is the approver's own key. A compromised control plane cannot manufacture authority it was never given.

EDR-0005 →

Delegation with a scope you can read

Object scope is proved statically; row scope is a transactional fence that aborts and tells you how many rows rather than silently narrowing your statement.

EDR-0007 →

Write the delegation in English

"Sam can update settings on sandbox accounts, up to 100 rows." A model compiles it; you read and sign the compilation; enforcement is deterministic from then on.

EDR-0016 →

Escalation, not refusal

Out-of-scope work routes to a chain of named humans — an agent's own principal first. Each stage adds only the authority it holds, and a timeout never approves.

EDR-0019 →

Routine work never queues

Standing orders are parameterised statements approved once, with per-parameter constraints. Support runs them all day without waking anybody.

EDR-0008 →

A machine reads it first

Static analysis plus a rehearsed, rolled-back run supply the facts; a model writes the summary. It is advisory input to a human, and it can never approve.

EDR-0009 →

Agents get scope, not credentials

An agent submits as itself for a named human, inside a scope it partly declares per task, and escalates the rest. It never holds a credential and can never approve.

EDR-0018 →

One URL to configure a client

Point the CLI at a deployment and it discovers the issuers, audiences, targets and relays it needs. There is nothing else to set up.

EDR-0002 →

Questions you can answer afterwards

The case for running this is mostly felt later — in an incident review, an audit, or the hour after something went wrong. These are the questions that are usually unanswerable, and what answers them here.

“Who changed this row, and who said they could?”

One query. The answer includes the statement text, the analysis the approver was actually looking at, and their signature over it.

EDR-0012 →

“Was that the model, or the person?”

A column, not an investigation. Anything an agent did carries both names — the actor and the human it acted for — and a one-name record is rejected at write time.

EDR-0018 →

“Did anyone know it was 412 rows?”

The rehearsed count is bound into what the approver signed, so what they were shown is provable after the fact rather than remembered.

EDR-0010 →

“Did that apply, or not?”

Including the honest answer. An execution whose outcome could not be established is recorded as indeterminate rather than guessed at in either direction.

EDR-0011 →

“What can this tool actually reach?”

A short list of roles and their grants, in the database’s own vocabulary. A bug in Marque’s scope checker is contained by the role, not by Marque.

EDR-0006 →

“Can we still work if Marque is down?”

A marque already issued keeps executing — the Pilot verifies it by computation, offline. The tool stays usable during the incidents it exists for.

EDR-0004 →

Start here