The undertaking with no home

By Monday morning, nearly everyone believes the launch decision is finished. A company is preparing to introduce an important new service for a large customer. The commercial case is strong. The customer has built its own plans around the date. One vendor, however, cannot quite satisfy a security requirement in the form the company normally expects.

The details are composite, but the predicament is familiar: real companies live by standards, and they also live where standards meet unfinished facts. A vendor may offer a compensating control. Counsel may revise a clause. A risk may be accepted by someone with the authority to accept it. A launch may proceed under a condition—or wait until the condition is met.

No one in this company is trying to take a shortcut. The security lead has described the gap and proposed a mitigation. Counsel has negotiated language that allocates responsibility more clearly. Procurement has collected the vendor’s attestations. Finance has estimated the cost of delay. The product leader is trying to keep faith with a customer. Each person has done a recognisable part of the work.

The wording is ordinary enough to be dangerous. Counsel’s redline says that the mitigation must be in place before customer data is processed. The security ticket shortens this to “verify before go-live.” In the steering deck, both have become a green status cell: Exception approved.

The contract has been revised. Security has reviewed the vendor’s material. The business sponsor has promised a date. A model has read the principal documents and produced the summary everyone wanted: the exception was approved, the remaining risk was acceptable and the launch could proceed.

The summary is useful. It is shorter than the email chain, clearer than the ticket history and easier to carry into a meeting than twelve open documents. It gives the people around the table a common account from which to act. That is why the mistake matters. The summary does not look irresponsible. It looks like relief.

Then the security lead notices what has disappeared. The latest screenshot from the vendor console still marks the mitigation planned, not verified.

Counsel approved the revised clause only on the condition that the mitigation be in place before customer data entered the system. The executive who accepted the exception remembers accepting a limited risk, not authorising a launch without that verification. He reads the summary again.

“That is not what I approved.” The model’s account is fluent, useful—and wrong at the point where language is about to become action.

Someone asks the question that the company’s systems ought already to answer:

Where, exactly, is the work?

The model conversation contains a persuasive account, but not the authority behind it. The contract repository contains the documents, but not the living state of the decision. The security ticket, approval workflow, email chain, vendor questionnaire, meeting notes and launch plan each hold a part. None can say, by itself, what the undertaking is for, what evidence the company has accepted, what remains unresolved, who may decide, what has been authorised or what has become true.

The company does not lack information. It may not even lack process. It lacks one place where the undertaking remains whole.

Such a place would have to preserve more than files. It would have to know which purpose governs when speed and security pull in different directions; which version of the contract controls; what the executive actually authorised; which condition remains open; what action is unavailable until that condition is met; and which record the institution will stand behind six months later.

Before generative AI, people often carried this unity by memory, professional habit and repeated conversation. That was expensive and fragile, but the seams were usually crossed by people who could notice when something had been lost. A model can now gather the fragments, give them one fluent voice and return that account to systems that act. The old absence has acquired a new force.

The organ and the body

The model became the visible centre of modern artificial intelligence for a simple reason: it speaks. A database does not lean forward and explain itself. A workflow does not draft the memorandum that carries a decision into the next meeting. A permissions service does not compare six documents, notice an ambiguity and propose a way through it. A frontier model can do all of these things with astonishing speed. It can make scattered material feel whole for the length of an answer.

Indwel was built to use that power fully. Fluency, however, does not make the speaker the owner of the work.

In the launch decision, the model is an organ of cognition. It can read, compare, infer, criticise and compose. It may notice a relationship that every human participant missed. It may save days of labour. Yet it did not originate the company’s purpose. It cannot lawfully amend that purpose. It cannot decide, by its own authority, which source the institution may rely upon. It cannot erase an open condition because the condition makes the answer untidy. It cannot grant its conclusion permission to expose customer data. It cannot declare the undertaking settled merely by reaching the end of a response.

Those offices belong to the cognitive act around the model: the people carrying responsibility, the records they may rely upon, the authorities under which they act, the obligations still open and the consequences that follow.

The AI industry understandably began with the model. The breakthrough was inference at extraordinary scale, so the first questions concerned the model’s behaviour: how to improve its answers, ground them in retrieved material, keep harmful outputs within bounds, give the model tools and place a human before certain actions. The surrounding systems have grown steadily more capable.

The governing centre, however, has usually remained the artificial participant. We govern what the model may see, what it may say, which tool it may call and whether a person must approve the call. Each new power receives another ring of control.

Indwel begins one level earlier. It asks what undertaking all of those powers have entered, and what order must remain intact while they contribute.

The organ can be extraordinary. The body still needs a constitution.

Where the work goes when it has no home

When an undertaking has no constitutional home, we place it in the nearest available object. The choices are sensible. Each keeps something the work needs. The trouble begins only when one part is asked to carry the whole.

Language and material

A conversation preserves language. It can retain the questions, responses, files and citations through which an inquiry developed. A workspace or collection gives that material continuity across sessions and makes it available to other people. For exploration, research and ordinary collaboration, these are powerful forms.

They do not, by themselves, tell the company which purpose governs, which version of the contract controls or whether a retrieved document has been admitted as Evidence for the proposition now in dispute. A conversation can end with a confident answer. A collection can contain every relevant file. The mitigation can still disappear between them.

A library gives the work a room. It does not necessarily give the work a state.

Execution and control

Agent runs, traces and workflows preserve a different part of the undertaking. A run can show the model’s plan, tool calls, observations, approvals and result. A trace can tell us what the software did, at what cost and in what order. A workflow can require approvals, route exceptions and enforce repeatable steps.

These mechanisms are indispensable. They can also operate perfectly upon the wrong account of the work. The trace may faithfully record that the model omitted the verification condition. The workflow may then advance because the incoming state says “approved.” The systems have preserved execution and control. They have not preserved the meaning counsel and security attached to the decision.

A record of what the machinery did can be exact without becoming an authoritative account of what the institution was entitled to do.

Enterprise representations and cases

Knowledge graphs, digital twins and enterprise ontologies can represent the vendor, contract, control, customer and service as related parts of one operational world. Case-management systems come closer still: they gather documents, participants, tasks and milestones around a knowledge-intensive objective, while allowing qualified people to choose among legitimate next actions as circumstances develop.1

These systems come close because they hold more of the enterprise together. Even so, a representation of the enterprise is not the same thing as the undertaking the enterprise is trying to finish. A case may record that an approval occurred without preserving the Evidence and open burden that made the approval conditional. It may close because the process has ended even though the proposition at its centre remains unverified.

A platform may display an objective field, documents, an approval button and an audit log. The harder test is whether those elements remain one constitutional state. Does the Objective survive later instructions? Is available material kept distinct from Evidence the institution has admitted? Can a completed task remain visibly different from a settled undertaking? Will the open burden survive the pressure—human or artificial—to make the work look finished?

Conversation, collection, run, trace, workflow, graph, twin and case can all serve serious cognition. The governed body of work is the thing they are serving: the undertaking whose identity, purpose, evidence condition, unresolved obligations, authority, causal development and terminal disposition must remain joined.

The work has always been larger than the worker

Long before a language model could join a meeting, several disciplines had learned that serious cognition does not fit inside one mind or one machine.

Consider the bridge of a large ship, the setting Edwin Hutchins studied in Cognition in the Wild. The ship’s position does not sit whole inside one navigator’s head, waiting to be spoken. Bearings are taken at different stations, called across the bridge, entered, transformed, plotted on a chart and checked through procedures carried by people with different responsibilities. Instruments, paper, speech, rank and trained habit all participate. No single person performs the entire computation. The navigation team knows where the ship is because the organised system keeps the information moving without losing what it means.2

What matters is not simply that several people take part. Each representation has a disciplined office. A spoken bearing becomes a written mark; the mark is plotted; the plot is checked; the result enters a decision by someone authorised to use it. If one transformation loses its meaning, the later precision of the chart cannot recover what was lost. The cognitive system succeeds because its handoffs preserve both information and office.

The launch decision is less dramatic, but structurally familiar. Counsel carries the force of a condition in a redline. Security carries the state of a mitigation in a ticket and a console. The executive carries the scope of the authority he exercised. The model carries an interpretation across documents. The steering deck carries a compressed status into the meeting. Cognition is already distributed. The question is whether the distribution preserves the undertaking or merely passes fragments of it along.

Later work on distributed cognition brought Hutchins’s insight directly into human–computer interaction. The design problem is not only what one user knows. It is how representations move, change form and coordinate action across people and artefacts.3 Lucy Suchman supplied the complementary warning: plans are useful, but they do not exhaust the situated course of work. People meet particulars, repair misunderstandings and act within circumstances no prior script fully contains.4 The plan remains; reality arrives.

Cognitive systems engineering therefore treats people and technology as a joint cognitive system. Its concern is not simply whether the machine behaved correctly or the human followed procedure. It asks whether the combined system maintained control under real conditions.5 That question belongs at the centre of enterprise AI. A model can operate exactly as designed while the wider system loses the distinction between evidence and assertion, proposal and authority, progress and completion.

Organisational routines and case-management research add another part of the picture. A routine has a prescribed form, but it also has a performed life: particular people interpret it in particular circumstances, preserving capability while adapting to what happens.6 Knowledge-intensive cases likewise cannot always be forced through one predetermined sequence. They advance through authorised judgement about what may legitimately happen next.7

Records scholarship insists that the resulting work leave durable evidence whose authenticity, integrity, usability and context survive organisational and technological change.8 Provenance standards give us a language for the entities, activities and agents involved in producing information.9 Systems engineering completes the inheritance with an end-to-end demand: some properties can only be guaranteed at the layer that possesses the meaning required to guarantee them.10

Together, these traditions tell us that the relevant unit is a working system; that action exceeds its plan; that judgement occurs within circumstances; that records must retain context; and that a whole-system property must be held at the level that understands the whole.

They also warn us against confusing representation with custody. The map may omit the circumstance that matters. The routine may be performed differently from the rule. The case may contain all its documents and still conceal a disagreement about what they establish. The record may be authentic and irrelevant. A provenance chain may be complete while the resulting action remains unauthorised.

The word constitutional names the order that prevents those fragments from usurping the organisation’s authority in turn. It does not turn every business decision into a courtroom or a miniature state. It means that the organisation has law before any one participant contributes; that the undertaking inherits purpose and authority under that law; that certain distinctions are protected; and that changes in state occur under rules the participants do not invent for themselves.

Indwel takes that inheritance into software. Organisations have always known, in practice, that work is distributed. What has changed is the arrival of a probabilistic participant able to interpret, summarise and act at almost every seam. The undertaking therefore needs an executable order of its own.

A body of work, governed

We already use the phrase body of work for things that belong together across time. Indwel gives the phrase a more exact office.

A governed body of Work is the durable undertaking through which an authorised organisation prosecutes an Objective under a Cognitive Contract while preserving Evidence, unresolved burdens, authorities, actions, Settlement, and continuity as the Work changes over time.

The object may contain documents, use workflows, call models, invoke agents, traverse graphs, and borrow generously from case management. Conversations, runs, traces, applications, and external systems may all contribute. None of those constituents, alone, is the whole.

The organisation is sovereign. The body of Work is the durable constitutional object through which that sovereignty becomes operational for an undertaking.

That distinction matters. To call Work constitutional is not to turn a business matter into a miniature state, nor to pretend that the Work itself possesses political sovereignty. It means that the undertaking has inherited law before any one participant contributes: an authorised purpose, admissible sources of Evidence, recognised offices, bounded capabilities, protected distinctions, and conditions under which institutional state may change.

Mark III names the enduring institutional law the Cognitive Constitution. Particular Work inherits and narrows that law through a Cognitive Contract. The Contract says what this Work is for, what Evidence may have standing, which people, models, agents, tools, and connectors may contribute, which offices may decide or veto, what effects may be attempted, what external frontiers must be crossed, what counts as Settlement, and what obligations must survive into continuity.

Authority narrows downward. A Work may receive less authority than the application, team, or institution above it. A user, agent, model, or question may receive less again. None may create authority its parent did not possess.

What keeps the undertaking whole is therefore more than persistence. A transcript can survive for years and still confuse a retrieved sentence with admitted Evidence, a recommendation with authority, a successful tool call with an observed effect, or a finished task list with Settlement. Continuity preserves time. Constitution preserves meaning through time.

The present state must remain legible. The institution needs to know whether the undertaking is proposed, disputed, conditionally authorised, awaiting Evidence, permitted for action, partially settled, refused, reopened, or carrying a future obligation. It also needs the causal path behind that state: which Evidence mattered, what inference contributed, who possessed authority, which burden was discharged, what effect occurred, and why the transition was allowed.

A new participant should inherit that governed state rather than a pile of old language. A replacement model may re-examine it, but it cannot rewrite what was authorised merely because it summarises the history differently. A new cloud, connector, or application surface may carry the Work without acquiring the power to redefine it.

A practical test is what remains when the meeting ends. Can the system say what the undertaking is for without asking the latest model to reconstruct the answer? Can it distinguish what is available from what the institution is entitled to rely upon? Can it preserve a condition everyone would prefer to forget? Can it say what was caused, what was observed, and what became true by authority rather than by narrative convenience?

On Tuesday morning, a colleague who was not present should be able to enter the Work and see the governing Objective, the applicable Contract, the Evidence the institution has admitted, the burdens still open, the authority currently available, and the action still unavailable. He should also see where genuine judgement remains.

The governed body of Work does not replace responsibility. It gives responsibility something whole upon which to act.

The same undertaking on Tuesday morning

On Tuesday morning, the vendor exception is still the same undertaking, although its Evidence, participants, and available capabilities may already have changed.

The organisation has not begun with a blank prompt. Its Cognitive Constitution already carries the relevant corporate authorities, security policy, contractual duties, privacy rules, delegation limits, records obligations, and operational constraints. The particular undertaking inherits those authorities through a Cognitive Contract.

The authorised executive then states the business purpose: launch the service for the waiting customer by a certain date, provided that the company’s security and contractual obligations are satisfied or lawfully excepted.

Indwel calls this the Objective. The capital letter marks a distinction between a request and the authorised purpose against which the Work will be judged. The Objective may be amended, but only under authority inherited through the Contract. A model may propose a clearer formulation or expose a conflict. It may not quietly redefine the undertaking as “launch as quickly as possible.”

The contract, security questionnaire, architecture diagram, vendor attestations, internal policy, meeting notes, cost estimate, and live system observations enter as Sources. Sources are material available to cognition. Availability is not standing.

Particular material is admitted as Evidence for particular propositions. The vendor’s attestation may support the claim that a control exists. An independent test may bear more strongly upon whether it works. The contract may establish what the vendor promised. Policy may establish the company’s requirement. Legal advice may govern how the clause is understood inside the company’s authority structure.

This is where the Evidence Firewall matters. Modern systems are extraordinarily good at putting material near a model. Mark III asks a different question: what may this Work rely upon, for which proposition, under what provenance, freshness, and limitation? AWA and governed acquisition can go outward to authoritative sources when a reasoning-critical fact is missing. The model’s recollection may suggest what to look for; it does not become Evidence by being remembered confidently.

The materials conflict. The vendor says its compensating control addresses the risk. Security agrees the control is plausible but says the configuration has not been verified. Legal approves revised language on the condition that verification occur before production data is introduced. The sponsor reports that delay may jeopardise the customer commitment.

The Work has reached a Frontier: the live edge between what has been established and what remains open. At that Frontier sits a burden. The burden is specific: establish that the promised mitigation is actually configured before the launch crosses the relevant boundary. In Mark III it can remain as an Attention Item and cognitive debt rather than disappearing because a summary prefers closure.

Now inference enters. One model reads the admitted Evidence, compares policy and contract, drafts a risk analysis, and proposes a sequence. Another may challenge its interpretation. Specialist inference may examine technical material. Governed retrieval may bring forward additional sources. A model may calculate the commercial cost of waiting, identify an alternative vendor, or discover a contradiction no one had noticed. This is serious cognition, and its output remains contribution.

Suppose a model writes: “The exception has been approved and the launch may proceed.” The sentence compresses three different states. Contractual wording was approved. Residual risk may have been accepted conditionally. Verification has not occurred. The summary turns a conditional path into an unconditional conclusion.

A conventional stack may now behave deterministically. The workflow sees “approved” and advances the gate. Identity confirms the executive’s role. A deployment tool receives valid credentials. An audit log records every step.

Nothing need malfunction locally. The constitutional error occurred when a probabilistic representation was allowed to become authoritative state.

Mark III prevents that crossing through the Inference Firewall, Cognitive Governors, and governed transition authority. The model may generate the sentence; generation is not commitment. The open burden remains represented. The approval remains typed as conditional. The capability to authorise production data remains unavailable. The customer commitment cannot manufacture permission to bypass the condition.

A security engineer later verifies the mitigation. The observation is admitted as Evidence against the open burden. The state changes because a governed transition permits the burden to be discharged. The Contract has not prescribed every intellectual step; it has governed the boundary at which intelligence may acquire consequence.

Notice what this arrangement permits. Models can be more adventurous because they do not authenticate themselves. Agents can prepare more work because capability is separately bounded. Human reviewers need not approve every harmless step because their office is invoked where authority actually matters. Tools and connectors can be powerful because their invocation and effects remain governed.

If an authorised decision-maker grants the exception, Governed Capability Invocation and the Sovereign Action Fabric carry the decision towards consequence. Permission, request, provider acceptance, actual effect, and observation remain different states. A successful external API call is not automatically proof that the intended institutional effect occurred.

Only then does Settlement determine what the Work may legitimately become. Settlement might establish that the exception is accepted for a defined period, the verified mitigation must remain active, the service may launch for the named customer and data class, a review is due on a specified date, and broader deployment remains unauthorised.

A Receipt preserves the authority, Contract, Evidence, inference, transition, effect, unresolved obligations, and reasons for that state. The Chronicle carries the Work forward. If the vendor later changes its architecture, a vulnerability appears, the exception expires, or a different model re-analyses the matter, the institution does not begin again from a pile of conversations. Temporal Cognition, scheduled Work, and Watchpoints can reopen the same undertaking when the future condition arrives.

Meanwhile Work Briefs, Cognitive Capital, Memory, Cognitive Threads, and explicit context selection let a new participant inherit the real state without promoting every remembered formulation into Evidence. Prepared Reciprocity can determine whether one precise human answer would materially advance the Work and what no-regret work should proceed before asking. Cross-Work Synthesis can later discover patterns among authorised vendor reviews without collapsing their separate Contracts.

The undertaking has outlived the meeting, the workflow, the model, and the Tuesday on which any one of them happened.

The seam where language becomes state

The most important moment in the case is not the model’s factual error by itself. Models make errors, and human beings do too. The critical moment is the seam at which an interpretation becomes institutional state.

A rule can be perfectly deterministic and still govern the wrong account of the work.

A control at one segment cannot protect a meaning that has already been changed at another.

A policy engine may reliably enforce the policy it is given. An approval service may reliably verify the role of the person who clicked. A tool gateway may reliably reject forbidden parameters. An audit system may reliably preserve the resulting events. Yet if a model has already changed the represented Objective, promoted context into Evidence, erased a burden, selected the wrong policy branch or declared an unfinished state complete, those deterministic mechanisms may preserve and execute the mistake.

The engineering follows a familiar rule: a system-level guarantee is only as strong as the material paths through which the protected state can change. Correct controls in several components do not cover a seam that lies outside them.

That is why one critical seam matters. The company may govern retrieval well, require a human approval, restrict the available tool and preserve an excellent audit trail. If the model can still turn a conditional approval into an unconditional state before those controls receive it, the constitutional property has already been lost for that execution. Later controls may detect, contain or correct the failure. They cannot make it true that the unauthorised transition never occurred.

Computer security has long expressed a related principle through complete mediation: protected operations must pass through an authoritative enforcement point rather than relying on an earlier check that may no longer describe the present state.11 System safety reaches the same conclusion from another direction. Harm can arise from inadequate constraints among components that are each functioning locally as designed.12

For a cognitive undertaking, the protected properties include purpose, authority, Evidence, unresolved burdens, consequential action, Settlement and terminal truth.

The model need not become predictable in every word. What must be predictable is the boundary at which its words become institutional state.

The seam is the difference between generation and commitment. Generation may be probabilistic, expansive and even unruly. Commitment changes the governed state of the undertaking. A model may offer ten interpretations; the constitution decides whether any one of them is admitted, which burden it changes, whether it affects capability and whether it may enter terminal truth.

Engineers already rely on this separation. A database may calculate candidate changes before a transaction commits. A compiler may explore transformations before producing an executable. A safety system may permit rich internal behaviour while tightly constraining the boundary at which that behaviour can affect the world. Sovereign Cognition applies the same seriousness to institutional meaning.

The model may explore boldly inside its office. It may propose several interpretations, argue with the current view and uncover something no person noticed. What it may not do is authenticate its own proposal into authority, Evidence or settled fact.

Inference is freer to be useful when it is not asked to impersonate institutional authority.

The systems nearest the boundary

Modern case and workflow platforms already govern sequences, roles, approvals and exceptions. Some now place AI agents inside deterministic orchestration, letting probabilistic reasoning handle ambiguity while a process engine governs execution.13

Enterprise ontology and decision-intelligence platforms connect operational data, business objects, permissions, logic and action. Palantir’s Ontology, for example, makes an enterprise’s operational world legible and executable; its AI platform adds human review and controlled action around model-assisted work.14 Aera, C3 AI and Quantexa bring together other strong combinations of enterprise context, decisions and governed execution.

Agent control planes and durable runtimes preserve another important part of the picture. They can checkpoint state, pause for approval, enforce tool policy, retain traces and resume long-running work. LangGraph, the OpenAI Agents SDK, Microsoft’s agent frameworks, Google’s agent platform and Amazon’s AgentCore all move agent systems toward greater operational control.15

The launch decision may already touch a contract system, a security platform, a ticketing service, an approval workflow and an agent runtime. Each product can perform its own office well. The risk lies in the handoff. Counsel’s condition may leave the contract system as an untyped comment. A security control may travel onward as “planned” when the next system expects “verified.” A model may compress both into “approved.” The workflow can then behave exactly as designed and still carry the wrong state forward.

Successful integration moves more than data. It carries the constitutional meaning of the data across the move.

A workflow can insist upon approval. An ontology can relate the vendor, control, contract, customer and service. A control plane can restrict an agent’s tools. A governance suite can inventory models and risks. The undertaking still needs continuous custody of the authorised purpose, admitted Evidence, open mitigation, permission to launch and final disposition.

That custody need not require a monolith. An enterprise may compose several excellent systems. But the Cognitive Constitution must then remain enforceable through the contracts between them, and every material handoff must preserve it. If a model, integration or human summary can turn a condition into an approval between components, the company no longer has one governed undertaking. It has several locally correct systems exchanging an institutional mistake.

Indwel brings familiar technologies into one order around the work. Persistence serves continuity. Provenance serves Evidence. Approval serves authority. Workflow serves governed transition. Deterministic control serves one Objective and one terminal truth.

That unbroken custody is what the product must preserve.

What the missing custody costs

The missing object rarely appears on a balance sheet under its own name. The company sees its effects elsewhere.

An executive asks for the decision to be reconstructed before he will sign. Counsel re-reads documents because the summary cannot be trusted. Two teams act upon different versions of the same approval. A customer receives a promise before its condition is satisfied. An auditor can reproduce system events but cannot explain why the institution believed it was entitled to act.

The direct error may be costly. More often, the expense accumulates quietly. A second meeting is held to recover the first. An analyst compares a generated summary against the source material line by line. Senior people perform clerical archaeology because the institution cannot safely rely upon its own account. A tool saves ten minutes of drafting and creates an hour of consequential review.

The organisation pays again for cognition it believed it had already completed.

That second payment seldom appears as an AI expense. It is scattered through legal time, security review, executive attention, customer delay and the quiet reluctance of capable employees to trust the new system at the moment of consequence. A pilot can look efficient while the organisation around it absorbs the unfinished work.

There is also a cost to caution. When the institution cannot see which condition is still open, it tends either to move too quickly or to stop everything. Responsible people ask for broad re-review because they cannot isolate the live burden. Controls multiply around entire classes of work because the system cannot state which particular transition is unsafe. The company becomes slower not because its standards are too high, but because its account of the undertaking is too weak to support a precise decision.

The same weakness burdens adoption. Employees learn that an AI answer is useful only until the moment somebody must rely upon it. They then recreate the old process beside the new one: the model drafts, while the people quietly rebuild the evidence, authority and history. What appears to be automation becomes an additional layer of production whose output must be governed somewhere else.

The model’s invoice may be small. The organisational bill arrives elsewhere: verification, correction, reconciliation, delayed decisions, failed actions, audit reconstruction and retained risk. Cheap output is not necessarily cheap work.

Dependence upon a model or conversation adds another cost. When the provider changes, the practical meaning of the undertaking has to be reconstructed from language. When a new model reaches a different conclusion, the institution has no independent constitutional state against which to judge the difference.

A governed body of work preserves the value of thought the organisation has already paid to perform. It also tells the organisation when that thought has become an outcome it may safely use.

Indwel begins with the undertaking

Indwel began with a practical conviction: consequential cognition should remain answerable to the authorised organisation whose purposes, duties, and authority give the cognition standing. We kept meeting the same problem in development. A model would do something genuinely impressive, yet the undertaking around the answer remained dispersed. Purpose lived in one surface, sources in another, an unresolved burden in somebody’s memory, policy in a document beside the system, and authority to act somewhere else again. The answer was good. The Work was still homeless. Mark III is the engineered answer to that dispersion.

The organisation supplies the Cognitive Constitution. The Work-specific Cognitive Contract makes the relevant law executable for a particular undertaking. Durable Work then carries Objective, Evidence, Frontier, authority, cognitive contribution, capability, effect, Settlement, Receipt, and Chronicle as one governed state.

Unity is the principal interface to that state, not the place where governance is invented. Ask Indwel is the conversational entrance to the same constitutional system. The Platform API and business-application engine expose server-owned constitutional primitives so applications can build Company Answers, Vendor Risk Review, Release Readiness, and other institutional experiences without re-creating authority in the client.

The customer should not have to write a constitutional treatise to begin ordinary Work. Natural language remains natural. The model may help clarify purpose, find ambiguity, suggest Evidence needs, and propose a route. Underneath, the system preserves the distinction between the user’s words and the authority those words actually carry.

Material that other systems flatten into “context” retains different offices. Retrieval can find a clause without admitting it as Evidence. Memory can preserve continuity without becoming authority. Cognitive Capital can retain a durable formulation while requiring explicit use admission. A Work Brief can orient a new participant without replacing the underlying state. The Frontier and Attention Items keep unresolved obligations visible. Cognitive Threads preserve long lines of reasoning without making a transcript the constitution.

Inference is equally plural. Mark III can route among model providers, specialist models, private or air-gapped inference, embeddings, deterministic computation, and human judgement. The Sovereign Microkernel and Sovereign Act Runtime keep those faculties subordinate to one sealed authority and one protected state. Changing the faculty does not change the Work’s law.

Capability is also separated from recommendation. Governed agents, tools, connectors, filesystems, databases, systems of record, and cloud services may be admitted to the Work. Operational frontiers such as DLP, malware scanning, classification, external policy, metering, security inspection, quarantine, and telemetry may inspect or constrain passage. The Action Fabric controls the boundary at which a decision can become an external effect. Settlement controls the boundary at which an effect can become institutional truth.

The result is not governance pasted around an AI system. It is a cognitive operating system in which inference, Evidence, memory, tools, people, effects, and continuity have explicit constitutional offices.

The customer should feel this as clarity rather than ceremony. The right purpose stays in view. The material the institution may rely upon is distinguishable from everything merely available. A condition cannot quietly vanish. The person responsible for judgement can see where judgement is actually needed. A later reviewer can inspect why the Work changed without asking a new model to invent the history.

This also changes model independence from a procurement feature into a constitutional property. An institution can change provider, cloud, agent framework, or application surface when capability, price, policy, or risk changes. The replacement inherits Work it did not create and law it may not silently redefine.

The model remains an extraordinary organ of cognition. The organisation remains sovereign. The Work remains the durable body through which its authorised cognition can continue.

The work remains

On Monday morning, the executive should not have needed to say, “That is not what I approved.” The condition should never have disappeared from the Work.

None of this requires perfect people or infallible models. Evidence will remain incomplete. Judgement will remain difficult. Policies will conflict. Business will remain uncertain. A governed body of Work offers something more useful than a promise to remove those realities: it keeps purpose, law, Evidence, uncertainty, authority, consequence, and continuity joined long enough for responsible cognition to occur.

The participants may change. The model may change. New Evidence may warrant another judgement. The Objective may be lawfully amended. A future Watchpoint may reopen the matter. What should not change by accident is the identity of the undertaking or the constitutional history that makes its changes intelligible.

The Work must outlive the model.

But Work does not create its own sovereignty. It inherits authority from the organisation through Cognitive Constitution and Cognitive Contract. That correction completes the proposition rather than weakening it.

The first requirement is a durable body of Work. The prior authority is institutional law. The next essay takes up the point at which the law becomes purpose: the Objective under which probability is allowed to serve.

The order is simple enough to state without collapsing its offices: the organisation writes the law; the Contract binds the Work; the Objective states what the Work is for; probability contributes within that order. That is Objective before probability.

Notes

Working glossary

Authority—the legitimate capacity to establish or amend the Objective, admit a transition, authorise an effect or confer Settlement.

Body of work—the persistent undertaking whose identity, purpose, evidence condition, burdens, authorities, actions and present truth remain joined over time.

Burden—a specific unresolved obligation that must be satisfied, preserved or expressly disposed before the work may advance through a relevant transition.

Chronicle—the continuing authoritative account of the body of Work’s state and constitutional history.

Cognitive Constitution—the authorised organisation’s enduring law for cognition: the authority from which policy, Evidence standing, offices, capability, effects, Settlement, and continuity descend.

Cognitive Contract—the binding Work-specific constitution that narrows inherited authority to a particular Objective and governs the terms under which cognition may establish, change, or cause institutional consequence.

Custody—the continuous preservation of the undertaking’s constitutional meaning across people, models, systems and material transitions.

Evidence—source material admitted for a defined proposition under stated provenance, relevance, authority and limitation.

Frontier—the present boundary between what the work has established and what remains unresolved or legitimately available to do next.

Objective—the authorised purpose and completion standard of the body of work.

Commitment—a transition by which a proposal changes the governed state of the undertaking or becomes capable of external effect.

Receipt—the reasoned record of a governed transition, including the authority, Evidence, burdens, decision and resulting state.

Settlement—the authorised determination that the body of work has reached a legitimate terminal or qualified state, or cannot yet do so.

Source—material available to the body of work before any claim is made about its admissibility or evidentiary force.


  1. Object Management Group, Case Management Model and Notation (CMMN), Version 1.1; Wil M. P. van der Aalst, Mathias Weske and Dolf Grünbauer, “Case Handling: A New Paradigm for Business Process Support,” Data & Knowledge Engineering 53, no. 2 (2005): 129–162.↩︎
  2. Edwin Hutchins, Cognition in the Wild (MIT Press, 1995).↩︎
  3. James Hollan, Edwin Hutchins and David Kirsh, “Distributed Cognition: Toward a New Foundation for Human–Computer Interaction Research,” ACM Transactions on Computer-Human Interaction 7, no. 2 (2000): 174–196.↩︎
  4. Lucy A. Suchman, Plans and Situated Actions: The Problem of Human–Machine Communication (Cambridge University Press, 1987), and the later Human–Machine Reconfigurations.↩︎
  5. Erik Hollnagel and David D. Woods, Joint Cognitive Systems: Foundations of Cognitive Systems Engineering (CRC Press, 2005).↩︎
  6. Brian T. Pentland and Martha S. Feldman, “Organizational Routines as a Unit of Analysis,” Industrial and Corporate Change 14, no. 5 (2005): 793–815.↩︎
  7. Van der Aalst, Weske and Grünbauer, “Case Handling.”↩︎
  8. International Organization for Standardization, ISO 15489-1:2016—Information and Documentation: Records Management—Part 1: Concepts and Principles.↩︎
  9. W3C Provenance Working Group, PROV Overview and PROV-O: The PROV Ontology (2013).↩︎
  10. Jerome H. Saltzer, David P. Reed and David D. Clark, “End-to-End Arguments in System Design,” ACM Transactions on Computer Systems 2, no. 4 (1984): 277–288.↩︎
  11. James P. Anderson, Computer Security Technology Planning Study, Volume II (1972), and the reference-monitor tradition that followed.↩︎
  12. Nancy G. Leveson and John P. Thomas, STPA Handbook (2018); Roel Dobbe, “System Safety and Artificial Intelligence” (2022).↩︎
  13. See the CMMN standard and current agentic-orchestration documentation from Camunda and UiPath.↩︎
  14. Palantir Technologies, current documentation for AIP, the Ontology, ethics and governance, and controlled actions.↩︎
  15. Current first-party documentation for LangGraph persistence and human-in-the-loop execution; OpenAI Agents SDK; Microsoft Agent Framework; Google Gemini Enterprise Agent Platform; and Amazon Bedrock AgentCore Policy.↩︎