{
  "abstract": "A flagship architecture thesis introducing Inert Agents, Capability Leases, the Agency Control Plane, Machine Sovereignty and Safe Agency Capacity as a coherent model for governing persistent autonomous software actors.",
  "author": {
    "email": "tony@malott.ai",
    "email_url": "mailto:tony@malott.ai",
    "id": "person:tony-malott",
    "name": "Tony Malott",
    "resume_url": "https://malott.ai/resume/",
    "url": "https://malott.ai/"
  },
  "card": {
    "kicker": "Agent Sovereignty · Trusted autonomy at population scale",
    "orientation": "The cloud is acquiring a population. The important question is not how many agents you can create, but how many you can trust to work.",
    "visual_motif": "ghost-field-authority-boundary"
  },
  "claims": [
    {
      "caveat": "Internet-Draft; work in progress, not an adopted IETF standard.",
      "id": "claim:ghosts:agents-as-workloads",
      "posture": "primary-emerging-standard-work",
      "support": [
        "source:ietf-ai-agent-auth-02"
      ],
      "text": "Current IETF work models AI agents as workloads requiring identity, credentials, authorization and delegated context."
    },
    {
      "caveat": "Provider limits are mutable and must be reverified when reused later.",
      "id": "claim:ghosts:workflow-scale",
      "posture": "dated-primary-vendor-fact",
      "support": [
        "source:cloudflare-workflows-limits"
      ],
      "text": "As verified August 12, 2026, Cloudflare Workers Paid documents up to 50,000 concurrent Workflow instances and up to 300 new Workflow instances per second per account."
    },
    {
      "caveat": "Proposed metric; not an industry standard or empirically normalized benchmark.",
      "id": "claim:ghosts:sac",
      "posture": "owner-proposed-architecture-metric",
      "support": [
        "source:shareplane-platform-issue-426"
      ],
      "text": "Safe Agency Capacity measures the amount of consequential autonomous concurrency an architecture can sustain while preserving governance invariants."
    }
  ],
  "collections": [
    {
      "id": "collection:ghostmesh",
      "position": 20,
      "title": "GhostMesh"
    },
    {
      "id": "collection:governed-ai-operations",
      "position": 20,
      "title": "Governed AI operations"
    }
  ],
  "dates": {
    "created": "2026-08-12",
    "evidence_verified": "2026-08-12",
    "published": "2026-08-12",
    "updated": "2026-08-12"
  },
  "evidence_authority": {
    "posture": "primary-source-current-facts-plus-explicit-owner-architecture-synthesis",
    "prior_art_disposition": "inert-agent-phrase-has-prior-use-architecture-definition-is-distinct",
    "receipt_path": "docs/publication/issue-426/EVIDENCE_RELATIONSHIP_AUTHORITY.json",
    "status": "complete"
  },
  "featured": true,
  "format": {
    "depth": "Narrative doctrine plus control-plane reference concepts",
    "interaction": "Cinematic static-first Ghost Field narrative with twelve semantic teaching scenes",
    "label": "Flagship architecture thesis",
    "reading_time": "22 min"
  },
  "id": "artifact:the-cloud-is-filling-with-ghosts",
  "lifecycle": {
    "authority_axes": {
      "creative": "complete",
      "evidence": "complete",
      "owner_acceptance": "granted",
      "relationships": "complete",
      "render_uat": "complete",
      "semantic": "complete"
    },
    "merge_authority": "granted",
    "owner_review": "accepted",
    "phase": "public-production",
    "production_authority": "granted",
    "state": "PUBLISHED",
    "terminal_target": "PUBLIC_PRODUCTION_VERIFIED"
  },
  "presentation": {
    "disposition": "NEW_FAMILY",
    "family": "presentation-family:ghost-field-agent-sovereignty-v1",
    "motif": "ghost-field-authority-boundary"
  },
  "presentation_status": "owner-accepted-ghost-field-v1",
  "production_promotion": {
    "acceptedArticleHead": "b34221a9042235635198401728ecb4e798295ccf",
    "acceptedArtifactDigest": "sha256:179f590f3230742e77ab1d7f8522c94cfdfe6e04b908353e054869b2ecb13c9b",
    "acceptedRouteSha256": "a182f1931426ba51cf70e84a4170ab3bcddfcc486850197f07165e2c09771dcc",
    "artifactId": "artifact:the-cloud-is-filling-with-ghosts",
    "authorityCommentId": 5275708307,
    "authorityMarker": "owner-production-authority:issue-426-cloud-filling-ghosts-v1",
    "authorizedMutation": "one-standard-production-deployment-after-accepted-merge",
    "governingIssue": 426,
    "ownerDecision": "Accepted for public publication after direct external corroboration links were surfaced and the same protected UAT gates passed.",
    "presentationFamily": "presentation-family:ghost-field-agent-sovereignty-v1",
    "pullRequest": 427,
    "requiredExternalCorroboration": [
      "https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/02/",
      "https://developers.cloudflare.com/agents/concepts/agentic-patterns/long-running-agents/",
      "https://developers.cloudflare.com/agents/",
      "https://developers.cloudflare.com/sandbox/guides/outbound-traffic/",
      "https://developers.cloudflare.com/workflows/reference/limits/",
      "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities",
      "https://docs.cloud.google.com/iam/docs/agent-identity-overview"
    ],
    "route": "/artifacts/the-cloud-is-filling-with-ghosts/",
    "schemaVersion": "1.0.0",
    "semanticRewriteAuthorized": false,
    "target": "public-production",
    "unrelatedMutationsAuthorized": false,
    "visualRedesignAuthorized": false
  },
  "provenance": {
    "ai_assistance": {
      "role": "Collaborative reasoning, terminology testing, architecture synthesis, primary-source research, manuscript drafting, information design, deterministic serialization and protected Development implementation under owner review.",
      "used": true
    },
    "boundary": "Current platform facts are dated and source-bound. Safe Agency Capacity, Machine Sovereignty and the generalized Capability Lease are explicitly presented as architectural synthesis rather than standards.",
    "posture": "Owner-originated architecture thesis developed during Control Tower commissioning and cross-checked against current primary standards and cloud-platform evidence.",
    "sources": [
      {
        "id": "source:shareplane-platform-issue-426",
        "locator": "https://github.com/pinklon/shareplane-platform/issues/426",
        "role": "Governs manuscript, vocabulary, evidence posture, Creative Lock, Development boundary and Owner UAT.",
        "title": "Publish The Cloud Is Filling With Ghosts as the Agent Sovereignty flagship",
        "type": "governing-publication-authority"
      },
      {
        "id": "source:ietf-ai-agent-auth-02",
        "locator": "https://datatracker.ietf.org/doc/draft-klrc-aiagent-auth/02/",
        "role": "Primary current work-in-progress source for agents as workloads, agent identity, delegated context, runtime credentials, missions and authorization.",
        "title": "AI Agent Authentication and Authorization, draft-klrc-aiagent-auth-02",
        "type": "primary-emerging-standard-work"
      },
      {
        "id": "source:cloudflare-long-running-agents",
        "locator": "https://developers.cloudflare.com/agents/concepts/agentic-patterns/long-running-agents/",
        "role": "Primary support for durable agent identity, durable state and wake-on-message actor behavior.",
        "title": "Cloudflare Long-running agents",
        "type": "primary-vendor-documentation"
      },
      {
        "id": "source:cloudflare-sandbox-egress",
        "locator": "https://developers.cloudflare.com/sandbox/guides/outbound-traffic/",
        "role": "Primary support for credential mediation outside the sandbox and egress-policy enforcement.",
        "title": "Cloudflare Sandbox outbound traffic",
        "type": "primary-vendor-documentation"
      },
      {
        "id": "source:cloudflare-workflows-limits",
        "locator": "https://developers.cloudflare.com/workflows/reference/limits/",
        "role": "Primary dated support for paid-account Workflow concurrency and creation-rate examples.",
        "title": "Cloudflare Workflows limits",
        "type": "primary-vendor-documentation"
      },
      {
        "id": "source:microsoft-entra-agent-id",
        "locator": "https://learn.microsoft.com/en-us/entra/agent-id/what-are-agent-identities",
        "role": "Primary support for distinct agent identity objects and agent-focused identity governance.",
        "title": "Microsoft Entra Agent ID",
        "type": "primary-vendor-documentation"
      },
      {
        "id": "source:google-agent-identity",
        "locator": "https://docs.cloud.google.com/iam/docs/agent-identity-overview",
        "role": "Primary support for runtime-bound agent identity and agent authentication to resources, MCP servers and other agents.",
        "title": "Google Cloud Agent Identity overview",
        "type": "primary-vendor-documentation"
      }
    ]
  },
  "public": true,
  "public_route": "/artifacts/the-cloud-is-filling-with-ghosts/",
  "public_safe_status": "owner-accepted-public-production",
  "reading_terminal": {
    "rationale": "The flagship closes on the strategic question of how much autonomy an architecture can safely carry; related doctrine and architecture Works continue the technical path."
  },
  "relationships": [
    {
      "label": "Authored by Tony Malott",
      "target_id": "person:tony-malott",
      "type": "authored_by"
    },
    {
      "label": "Governed by SharePlane Platform Issue #426",
      "target_id": "issue:shareplane-platform:426",
      "type": "governed_by"
    },
    {
      "explanation": "The earlier Work establishes the durable control-plane boundary; this Work generalizes it into machine-authority governance at population scale.",
      "label": "The Agent Is Not the Product. The Control Plane Is.",
      "reader_group": "foundations",
      "target_id": "artifact:the-agent-is-not-the-product-the-control-plane-is",
      "type": "related_to"
    },
    {
      "explanation": "The origin story explains continuity through replaceable workers; this Work explains how persistent software actors should acquire and lose authority.",
      "label": "GhostMesh Was Waiting for Its Technology",
      "reader_group": "companions",
      "target_id": "artifact:ghostmesh-was-waiting-for-its-technology",
      "type": "companion_to"
    },
    {
      "explanation": "The operational crossing supplies concrete field evidence for claims, leases, ephemeral credentials and receipts.",
      "label": "The Mesh Is No Longer a Diagram",
      "reader_group": "applications",
      "target_id": "artifact:the-mesh-is-no-longer-a-diagram",
      "type": "builds_on"
    }
  ],
  "route": "/artifacts/the-cloud-is-filling-with-ghosts/",
  "schema_version": "2.0.0",
  "semantic_status": "owner-locked",
  "slug": "the-cloud-is-filling-with-ghosts",
  "source": {
    "content_status": "owner-approved-canonical-manuscript",
    "format": "markdown",
    "path": "content/artifacts/the-cloud-is-filling-with-ghosts/source.md",
    "public_projection_name": "Ghost Field v1"
  },
  "source_authority": {
    "doctrine_companion": "ghostmesh-agent-sovereignty@1.0.0",
    "governing_issue": 426,
    "projection": "canonical SharePlane shell plus owner-locked Ghost Field presentation",
    "reference_architecture_companion": "ghostmesh-agent-sovereignty-reference@1.0.0",
    "semantic_version": "cloud-is-filling-with-ghosts@1.0.0"
  },
  "subtitle": "The Agent Army Needs a Constitution",
  "thesis": "The cloud increasingly contains persistent non-human actors, so the strategic infrastructure problem is how to govern machine authority at population scale without surrendering control.",
  "title": "The Cloud Is Filling With Ghosts",
  "topics": [
    "ghostmesh",
    "control-tower",
    "agent-sovereignty",
    "ai-agents",
    "non-human-identity",
    "authorization",
    "capability-security",
    "cloud-architecture",
    "control-planes",
    "safe-agency-capacity",
    "machine-sovereignty"
  ],
  "type": "flagship-agent-sovereignty-architecture-thesis",
  "voice": {
    "authority": "$write-in-tonys-voice",
    "reconciliation_receipt": "content/artifacts/the-cloud-is-filling-with-ghosts/TONY_VOICE_RECONCILIATION_v01.json"
  }
}
