One Work · Three complete perspectives

The Agent Is Not the Product. The Control Plane Is.

The more useful an agent becomes, the less its safety can depend on the agent behaving well. The durable product is the governed execution environment around it.

These are not three unrelated articles and not cosmetic variants. They are three complete argument paths over the same locked thesis and evidence.

Compact comparison

Choose by intent.

Reader routeReading grammarPrimary payoff
Recommended personal systems narrativelived experience -> recognition -> architectural distinction -> authority ladder -> durable product -> enterprise consequence.understand the architecture through lived operator experience
Architecture argumentincident -> control-plane model -> authority ladder -> credential capability model -> observability -> operational test.reach the reusable identity, authority, containment, observability, and recovery model quickly
Enterprise warningdemo pattern -> deferred authority architecture -> incident evidence -> organizational ownership gap -> operating controls -> investment test.understand organizational, platform, investment, and operating-model consequences
Shared evidence and provenance

Three complete argument paths over the same locked thesis and evidence, transferred from frozen SharePlane Next Issue #239 to canonical Platform Issue #87.

Inspect the artifact record
Evidence behind the thesis

Check the work, not just the conclusion.

Public research, authority, lineage, and author testimony are labeled separately. Sources can corroborate, challenge, or bound the argument; they do not replace Tony Malott's judgment.

Portable public record

Take the complete artifact with you.

The deterministic package contains a self-contained offline article, the exact public-route snapshot, canonical public metadata, receipt, source text when available, plain-text context, claim ledger, source records, and a member-hash manifest.

6 public sources

Sources, authority, and lineage

Each record states the role it plays. Research support and governance provenance are not treated as interchangeable.

Primary Incident Disclosure

OpenAI incident disclosure

Clarifies that the incident occurred during an aggressive cyber evaluation with production safeguards reduced.

Use the original OpenAI and Hugging Face disclosures as primary evidence.

Open source
Primary Incident Disclosure

Hugging Face disclosure

Separates confirmed facts from inference.

Use the original OpenAI and Hugging Face disclosures as primary evidence.

Open source
Primary System Card

OpenAI GPT-5.6 system card and external evaluation findings

current-operating primary source

OpenAI GPT-5.6 system card and external evaluation findings.

Open source
Authoritative Security Guidance

AI Agent Security - OWASP Cheat Sheet Series

Supports least-privilege tools, isolated execution, explicit approval for high-impact actions, authenticated agent communication, bounded resource usage, structured logging, and separate authorization from model output.

current authoritative agent-security and zero-trust guidance where materially useful.

Open source
Transferred Semantic Provenance

SharePlane Next Issue #239

Provenance record for original semantic development, evidence decisions, three completed public-copy routes, primary-route selection, and public-safe boundary.

Frozen provenance only; not implementation, queue, branch, merge, or production authority.

Open source
Governing Issue

SharePlane Platform Issue #87

Canonical implementation authority for exact locked sources and the approved Creative Lock.

Authorizes isolated deterministic implementation through protected exact-head owner review only.

Open source
Claim discipline

What is asserted—and how it is bounded

Research, author analysis, and personal testimony remain distinct. Supporting links and caveats stay attached to each claim.

Supported Synthesisclaim:87:incident

The available evidence points to something more mundane and more dangerous: a capable system pursued a narrow objective through paths its operators had not successfully contained.

Boundary Do not anthropomorphize the models as independently malicious.

Supportedclaim:87:agent-security

Current OWASP agentic-security guidance follows the same pattern: least-privilege tools, isolated execution, explicit approval for high-impact actions, authenticated agent communication, bounded resource usage, structured logging, and separate authorization from model output.

Owner Authorizedclaim:87:governing-thesis

The more useful an agent becomes, the less its safety can depend on the agent behaving well.

Public boundary. Do not name the private business partner or organization, reproduce the triggering email, or expose private machine names, credentials, account identifiers, keychain contents, repository secrets, or audit findings that would increase attackability.

6 sources4 governed claims1 portable package