HOW IT WORKS
Safe Stop
AG Arch uses Safe Stop when it cannot identify a valid governed path forward.
At that point, continuing would require one of three things:
- acting outside the current mandate;
- using a capability that is not suitable or safe for the work;
- proceeding without enough reality or evidence to justify the next action.
Safe Stop therefore means:
AG Arch stops execution deliberately, preserves the state of the work, and records why continuation is not currently valid.
This is not the same as a crash, timeout, or abandoned task.
It is a governed terminal or paused condition.
Why Safe Stop exists
Autonomous systems need to be able to stop for the same reason they need to be able to act.
Without a valid stopping mechanism, an agent under pressure to “finish the task” may:
- keep retrying a failing path;
- expand scope on its own;
- choose an unsuitable tool;
- weaken verification requirements;
- improvise around missing authority;
- continue after the environment has become unsafe or unclear.
AG Arch prevents that by making stopping itself a valid governed action.
Current AG Arch runtime semantics already distinguish explicit stop and terminal outcomes such as `STOP_RETURN_TO_OPERATOR` and `FAILED_TERMINAL` rather than treating every non-success result as the same state.
Safe Stop happens after other valid recovery paths are evaluated
Safe Stop is not the first response to difficulty.
AG Arch first determines whether the work can continue through:
Replan — change the route.
Re-authorize — change the mandate through Human Authority.
Reroute — use another capability.
Safe Stop becomes appropriate when none of those currently produces a valid path.
For example:
- no revised plan fits the mandate;
- required authority has not been granted;
- no suitable capability is available;
- a critical source of truth cannot be reached;
- the system cannot obtain evidence required to proceed safely.
AG Arch then stops rather than inventing another path.
Safe Stop preserves the current reality
Stopping execution does not mean forgetting everything that happened.
AG Arch preserves the state reached so far.
That can include:
- the original intent;
- current reality;
- success criteria;
- governed mandate;
- actions already performed;
- handoffs;
- observations;
- evidence;
- the current verdict;
- the condition that caused the stop.
This is essential because the system may have already changed the real environment.
If work resumes later, it must begin from that resulting state rather than replaying the original task blindly.
AG Arch records why the work stopped
A useful Safe Stop needs a concrete reason.
For example:
Required production change is outside the current mandate.
or:
The authoritative runtime state cannot currently be observed, so the required outcome cannot be verified.
or:
No available capability can perform the required action within the existing constraints.
This makes the stop actionable.
A human or later autonomous process can see what condition must change before the task can continue.
Safe Stop can be temporary
Safe Stop does not necessarily mean that the work can never continue.
The blocking condition may later disappear.
For example:
- an unavailable service may return;
- a suitable capability may become available;
- Human Authority may provide a new mandate;
- missing evidence may become accessible;
- the external environment may become safe again.
When that happens, AG Arch can re-establish current reality and resume from the appropriate lifecycle stage.
The preserved traceability makes that possible without pretending that the earlier execution never happened.
Safe Stop can also be final
Some situations do not have a valid continuation.
Human Authority may reject the required scope expansion.
The intended action may be prohibited.
The required capability may not exist.
Evidence may show that the requested outcome cannot be achieved under the existing constraints.
In those cases, Safe Stop can become the final state of the governed work.
The important point is that AG Arch ends with an explicit, explainable state rather than a false successful outcome.
Safe Stop is not the same as NOT PROVEN
`NOT PROVEN` is a verdict about the outcome.
Safe Stop is a decision about execution.
For example:
AG Arch may have a `NOT PROVEN` result because evidence is incomplete.
If the missing evidence can be collected, execution continues.
If the evidence system is unavailable but another valid source exists, AG Arch may Replan.
If collecting the evidence requires another specialist, AG Arch may Reroute.
Only when no valid continuation exists does AG Arch enter Safe Stop.
So:
NOT PROVEN asks: “Do we have proof of the outcome?”
Safe Stop says: “We currently have no valid governed path to continue.”
Safe Stop is not a request for arbitrary human intervention
A Safe Stop may surface the work to a person, but that does not mean:
“The AI failed — human, please figure it out.”
AG Arch should preserve enough information to explain:
- what was attempted;
- what is true now;
- what blocked continuation;
- which recovery paths were available;
- why they were insufficient;
- what condition would allow the work to resume.
If the unresolved condition requires a human authority decision, that decision is explicit.
If the problem is technical, the stop remains a technical state until a valid technical path becomes available.
Example — changing a system configuration
Continuing the same example:
AG Arch has determined that the running service needs a reload before the new configuration can become active.
The mandate allows the reload.
However:
- the current capability cannot perform it;
- no other suitable capability is currently available;
- the service state cannot be safely modified through any authorized alternative.
AG Arch first evaluates Reroute.
No valid target exists.
The plan itself is still correct, so Replan does not solve the problem.
The mandate is already sufficient, so Re-authorize is unnecessary.
AG Arch therefore enters Safe Stop.
It preserves:
- the correct configuration already written;
- the fact that the running service still uses the previous value;
- the existing mandate;
- the failed capability route;
- the health evidence;
- the unresolved requirement for a service reload.
The work can later resume if an appropriate infrastructure capability becomes available.
Until then, the outcome remains:
NOT PROVEN
and execution remains:
SAFE STOP
What Safe Stop adds to AG Arch
Safe Stop gives autonomous execution a controlled endpoint when further action is not justified.
It ensures AG Arch can say:
I know what has happened.
I know why the work cannot continue.
I know what condition would have to change before it can resume.
That completes the Recovery model:
NOT PROVEN → Diagnose Cause
→ Replan — change the path → Re-authorize — change the mandate through Human Authority → Reroute — change the capability → Safe Stop — preserve state when no valid path remains
Together, these recovery paths allow AG Arch to continue autonomous work when possible and stop it deliberately when continued autonomy is no longer justified.