HOW IT WORKS
04 — Recovery
Recovery begins when Observe & Prove returns a result that is not yet a verified outcome.
AG Arch does not treat that as a generic failure. It uses the evidence already collected to determine what blocked the outcome and where the work needs to return.
The recovery flow is:
Verdict → Cause → Recovery Path → Re-entry into the lifecycle
The goal is to continue from the real current state without discarding valid work or repeating the whole task unnecessarily.
Verdict
AG Arch reduces the outcome decision to two public states:
PROVEN
or
NOT PROVEN
The verdict answers:
Does the evidence prove the success criteria defined before execution?
PROVEN
AG Arch returns PROVEN when the required evidence supports the intended outcome.
That means the chain is complete:
Intent → Success Criteria → Execution → Observation → Evidence → Verdict
The work can then move to Verified Outcome.
AG Arch does not derive `PROVEN` from an agent's confidence, a successful command, or the absence of an error.
It derives it from the evidence required for that outcome.
NOT PROVEN
AG Arch returns NOT PROVEN when the available evidence cannot establish the required outcome.
That may happen because:
- the expected change did not happen;
- only part of the outcome was achieved;
- required evidence is missing;
- observed reality contradicts the expected result;
- the plan no longer fits the current state;
- the selected capability could not complete the work;
- the next required action is outside the current mandate.
`NOT PROVEN` does not automatically mean that everything failed.
It means AG Arch cannot close the work as a verified outcome yet.
AG Arch identifies why the outcome is not proven
The next step is not simply “try again”.
AG Arch uses the task history, current reality, execution receipts, and evidence to classify the blocking condition.
The important question becomes:
What has to change for this work to continue correctly?
That diagnosis determines the recovery path.
For example:
- if the route toward success is wrong, AG Arch returns to planning;
- if the required action is outside the mandate, AG Arch returns to Human Authority;
- if the capability is unsuitable, AG Arch routes the work elsewhere;
- if no valid path exists, AG Arch stops the work safely.
Recovery preserves the work already completed
AG Arch does not normally restart from the original request as if nothing happened.
It preserves the relevant state of the task:
- current reality;
- success criteria;
- mandate;
- actions already taken;
- observations;
- evidence;
- failed or partial attempts.
This matters because execution may already have changed the environment.
Recovery therefore starts from the state that exists now, not from the state that existed when the task first began.
Traceability provides the history needed to do that.
Replan
AG Arch chooses Replan when the intended outcome is still valid but the current route toward it is no longer appropriate.
Typical reasons include:
- an assumption used by the original plan turned out to be wrong;
- reality changed;
- an action produced an unexpected intermediate state;
- a dependency requires a different sequence;
- another valid execution path is now more appropriate.
AG Arch keeps the existing intent and success criteria, updates the plan using current reality, and continues from the appropriate point in the lifecycle.
Replan does not automatically require human involvement if the revised path still fits inside the existing mandate.
Re-authorize
AG Arch chooses Re-authorize when it knows what needs to happen next, but that action is outside the current governed mandate.
This is the recovery path that returns to Human Authority.
For example, execution may reveal that completing the work requires:
- changing another environment;
- expanding the scope;
- performing an exceptional or irreversible action;
- making a decision the autonomous system was never authorized to make.
AG Arch does not convert technical capability into permission.
Instead, it exposes the exact authority gap:
what action is required, why it is required, and which existing boundary prevents it.
Human Authority can then change the mandate, reject the expansion, or choose another direction.
If a new mandate is granted, AG Arch resumes autonomous execution inside the new boundary.
Reroute
AG Arch chooses Reroute when the plan and mandate remain valid but the current capability is not the right one to continue.
For example:
- a specialist lacks the required tool;
- the required environment is inaccessible to the current executor;
- another capability has the appropriate expertise;
- the current capability fails but an authorized alternative exists.
AG Arch keeps the governed work intact and transfers it to another suitable capability from the Capability Pool.
The handoff preserves the same:
- intent;
- success criteria;
- mandate;
- constraints;
- proof requirements.
Rerouting changes who performs the work, not what the work means.
Safe Stop
AG Arch chooses Safe Stop when it cannot identify a valid governed path forward.
That may happen when:
- every available execution path violates the mandate;
- no suitable capability exists;
- required reality cannot be established;
- a critical dependency is unavailable;
- continuing would require unsafe improvisation;
- the evidence shows that the current work cannot proceed responsibly.
Safe Stop is not AG Arch abandoning control.
It is AG Arch preserving control when continuation would no longer be justified.
The task remains traceable, including:
- the current state;
- what was attempted;
- why execution stopped;
- what evidence led to the stop;
- what would need to change before work could resume.
Recovery remains autonomous whenever possible
AG Arch does not send every `NOT PROVEN` result to a person.
It first determines whether the problem can be resolved inside the existing mandate.
A different plan may be enough.
A different capability may be enough.
Another observation may be enough.
Only Re-authorize necessarily returns to Human Authority because the required decision changes the boundary under which autonomous work is allowed to operate.
This preserves the intended division of responsibilities:
Humans define or change authority.
AG Arch handles execution and recovery inside that authority.
Example — changing a system configuration
The intended outcome is:
- the approved configuration is active;
- the running service uses it;
- the service remains healthy;
- unrelated configuration remains unchanged.
Execution changes the configuration source.
Observation then shows:
- the new value exists;
- the running service is still using the previous value.
AG Arch returns:
NOT PROVEN
It then uses the evidence to identify the cause.
If the service simply requires an authorized reload, AG Arch can Replan and continue.
If the reload requires an operation outside the existing mandate, AG Arch selects Re-authorize and returns that specific decision to Human Authority.
If the reload is allowed but the current capability cannot perform it, AG Arch Reroutes the governed work to another suitable capability.
If no authorized and safe route exists, AG Arch enters Safe Stop and preserves the current state and evidence.
The same verdict can therefore produce different recovery actions because AG Arch responds to the cause, not merely to the word `NOT PROVEN`.
What Recovery adds to AG Arch
Recovery closes the loop between verification and continued autonomous work.
AG Arch does not end with:
action → success/failure
It operates as:
Action → Observation → Evidence → Verdict
and, when needed:
NOT PROVEN → Cause → Replan / Re-authorize / Reroute / Safe Stop
This allows autonomous work to adapt when reality differs from the original plan while keeping intent, Human Authority, evidence, and execution connected.