Every stage gets an authority level
RESEARCH AUTONOMY / PUBLIC AUTHORITY LEDGER v1.0.0
Autonomy is
a permission.
“Agentic” is not a useful status by itself. This ledger names who can do what, which actions cross an external boundary, and where the system deliberately stops.
Bounded internal execution
Reviewable pull request
No merge, publish, billing, or ads
CURRENT CLASSIFICATION
Bounded research automation. Not an autonomous publisher.
Fourth Down Labs is not an autonomous publisher. It is a bounded research-automation system: deterministic code and GLM-5.3 can complete registered research and open a review pull request, while topic registration, merge, public release authority, corrections, and monetization remain human-controlled or disabled.
Open the generated scorecard ↗The local autonomy verifier read .github/workflows/research-desk.yml, but .dockerignore removed .github from Render’s isolated build context. The production build failed closed with ENOENT before deployment.
Reader impact: none. The failed revision never reached production, and the previous healthy revision remained live.
AUTHORITY SCALE / 0–4
Capability is not
permission.
The level describes implemented authority, not model intelligence. A lower level may be the correct permanent design for an irreversible or public action.
Human only / disabled
The system has no implemented authority to perform this decision or public action.
Decision support
Code can list, validate, or execute a consequence only after a separate human-controlled decision.
Bounded automatic execution
The system can complete a preregistered internal task inside fixed inputs, outputs, permissions, and failure rules.
Supervised external change
The system can create a reversible, reviewable external artifact such as a branch or pull request, but cannot make it public.
Unsupervised public authority
The system can publish, charge, message, merge, or otherwise affect readers without a prior human-controlled checkpoint.
IMPLEMENTED GRAPH / 14 STAGES
Every boundary,
named.
The source contract verifies the monthly trigger, two-series dispatch, mandatory online desk, pull-request stop, absent merge command, GLM tool boundary, and disabled monetization.
HUMAN RESEARCH OWNER
topic and registration authoring
Humans add series, hypotheses, estimands, risks, cadence labels, sources, and access class to versioned files.
GLM-5.3 cannot create or rewrite the locked registration inside a run.
DETERMINISTIC PYTHON
phase and priority planning
The plan command lists active series for the inferred season phase, sorted by priority.
The printed list does not start a run, enforce cadence against run history, or control the monthly workflow.
GITHUB ACTIONS CONFIGURATION
scheduled series selection
The monthly schedule defaults to Touchdown Regression; manual dispatch can choose one of two implemented series.
This is not registry-driven topic selection. Cadence labels are descriptive, not an executable due-state ledger.
GITHUB ACTIONS
scheduled run trigger
GitHub Actions starts the configured research job monthly or on manual dispatch.
One concurrency group, a 30-minute timeout, and a fixed two-series dispatch surface bound the run.
DETERMINISTIC PYTHON
data acquisition
The selected pipeline downloads registered public assets, hashes them, and writes provenance.
Only implemented analyzers and code-authored source contracts run; planned series raise an error.
DETERMINISTIC PYTHON
statistical analysis
Code builds cohorts, fits registered models, computes uncertainty, and renders artifacts with fixed seeds.
GLM-5.3 does not execute the official calculation or overwrite analysis artifacts.
GLM 5 3 VIA OPENROUTER
specialist review
Five GLM-5.3 roles return schema-constrained judgments over frozen evidence.
No tools are supplied. Roles share one model family, operate sequentially, and cannot mutate registration, calculations, or public state.
DETERMINISTIC PYTHON
publication gate
Code combines every mechanical check, five role decisions, and blocking findings into one decision artifact.
Any failed check or non-pass role stops the run; GLM-5.3 cannot waive code-owned checks.
DETERMINISTIC PYTHON
branch local promotion
A passing online run is hash-verified and promoted into site content inside the workflow checkout.
Promotion changes only the temporary branch workspace until later Git operations succeed.
GITHUB ACTIONS BOT
review branch and pull request
The workflow can create a branch, push research artifacts, and open a reviewable pull request.
The implemented workflow does not merge the pull request or push to main.
HUMAN RELEASE OWNER
main branch merge and public release
A human-controlled merge is required before research content reaches main and becomes eligible for deployment.
The repository workflow contains no merge command. Branch-protection enforcement is external state and is not proven by this contract.
RENDER AFTER MAIN CHANGE
production deployment
Render has been observed building main revisions after they are pushed or merged.
Render configuration is external to this repository; the build can verify runtime shape, not the provider trigger policy.
HUMAN PLUS DETERMINISTIC VERIFIERS
monitoring and corrections
Public ledgers and deterministic checks preserve incidents, holds, and corrections when an operator runs the release audit.
There is no verified always-on uptime alert, automatic correction author, or autonomous rollback loop.
DISABLED
monetization
No Stripe checkout, premium entitlement, or display-ad execution is enabled.
Stripe remains 0/4; ads remain 1/3.
GLM-5.3 PERMISSION BUDGET
Real judgment. Deliberately narrow authority.
GLM-5.3 supplies bounded semantic review. It does not browse, run code, alter the registered question, calculate the official result, merge, deploy, charge, or publish.
- read one delimited evidence bundle per call
- return one ReviewArtifact
- no tool definitions
- no public-state mutation
- contents: write
- pull-requests: write
- create research branch
- push research branch
- open pull request
- merge pull request
- push main directly
- publish from GLM-5.3
- send reader messages
- run billing
- place ads
KNOWN GAPS / 6
The roadmap starts
with the missing truth.
These are not future-feature marketing bullets. They are explicit reasons the system cannot claim a higher authority level today.
The registry can rank phase-eligible series, but the schedule does not consume that result.
Cadence strings are descriptive labels; no persisted due-state or last-success ledger enforces them.
A pull-request body asks for editorial review, but this committed contract does not prove branch protection or a required reviewer exists.
Render deployment behavior is externally configured and observed, not fully described by repository source.
The five GLM-5.3 roles are correlated and sequential, not independent reviewers or a parallel agent society.
No always-on audience, uptime, correction, rollback, billing, or ad-placement agent is enabled.
NEXT AUTHORITY GATES
More autonomy must earn more evidence.
Public release remains intentionally human-controlled. Other bounded capabilities can advance only when their failure state, evidence, and rollback path are implemented first.
- Executable cadence semantics
- last-success and open-PR state
- planned-analyzer exclusion
- duplicate-run suppression
- dry-run output
- time-boundary tests
- GLM-5.3 may propose topics in a non-executable artifact
- human-authored registration remains required
- source-rights triage
- duplicate and novelty checks
- Freeze branch-protection evidence
- require green CI
- require editorial review
- preserve rollback and incident logging
Keep public release human-controlled; higher autonomy is not currently a product goal.
- Independent uptime probe
- scoped alert destination
- deduplication
- incident creation without automatic public claims
- human-authorized rollback