Autonomy is
a permission.

“Agentic” is not a useful status by itself. This ledger names who can do what, which actions cross an external boundary, and where the system deliberately stops.

IMPLEMENTED STAGES14

Every stage gets an authority level

GLM-5.3 MAXIMUML2

Bounded internal execution

HIGHEST WORKFLOW ACTIONL3

Reviewable pull request

AUTONOMOUS PUBLIC AUTHORITYL0

No merge, publish, billing, or ads

Bounded research automation. Not an autonomous publisher.

Fourth Down Labs is not an autonomous publisher. It is a bounded research-automation system: deterministic code and GLM-5.3 can complete registered research and open a review pull request, while topic registration, merge, public release authority, corrections, and monetization remain human-controlled or disabled.

Open the generated scorecard ↗
BUILD-001 / FIXED BEFORE PUBLICATION

The local autonomy verifier read .github/workflows/research-desk.yml, but .dockerignore removed .github from Render’s isolated build context. The production build failed closed with ENOENT before deployment.

Reader impact: none. The failed revision never reached production, and the previous healthy revision remained live.

Capability is not
permission.

The level describes implemented authority, not model intelligence. A lower level may be the correct permanent design for an irreversible or public action.

LEVEL 03 STAGES

Human only / disabled

The system has no implemented authority to perform this decision or public action.

LEVEL 14 STAGES

Decision support

Code can list, validate, or execute a consequence only after a separate human-controlled decision.

LEVEL 26 STAGES

Bounded automatic execution

The system can complete a preregistered internal task inside fixed inputs, outputs, permissions, and failure rules.

LEVEL 31 STAGES

Supervised external change

The system can create a reversible, reviewable external artifact such as a branch or pull request, but cannot make it public.

LEVEL 40 STAGES

Unsupervised public authority

The system can publish, charge, message, merge, or otherwise affect readers without a prior human-controlled checkpoint.

Every boundary,
named.

The source contract verifies the monthly trigger, two-series dispatch, mandatory online desk, pull-request stop, absent merge command, GLM tool boundary, and disabled monetization.

01 / LEVEL 0human authored

HUMAN RESEARCH OWNER

topic and registration authoring

IMPLEMENTED CAPABILITY

Humans add series, hypotheses, estimands, risks, cadence labels, sources, and access class to versioned files.

HARD BOUNDARY

GLM-5.3 cannot create or rewrite the locked registration inside a run.

HUMAN ONLY / DISABLED2 EVIDENCE SURFACES
02 / LEVEL 1advisory only

DETERMINISTIC PYTHON

phase and priority planning

IMPLEMENTED CAPABILITY

The plan command lists active series for the inferred season phase, sorted by priority.

HARD BOUNDARY

The printed list does not start a run, enforce cadence against run history, or control the monthly workflow.

DECISION SUPPORT2 EVIDENCE SURFACES
03 / LEVEL 1fixed default or manual choice

GITHUB ACTIONS CONFIGURATION

scheduled series selection

IMPLEMENTED CAPABILITY

The monthly schedule defaults to Touchdown Regression; manual dispatch can choose one of two implemented series.

HARD BOUNDARY

This is not registry-driven topic selection. Cadence labels are descriptive, not an executable due-state ledger.

DECISION SUPPORT1 EVIDENCE SURFACES
04 / LEVEL 2bounded and automatic

GITHUB ACTIONS

scheduled run trigger

IMPLEMENTED CAPABILITY

GitHub Actions starts the configured research job monthly or on manual dispatch.

HARD BOUNDARY

One concurrency group, a 30-minute timeout, and a fixed two-series dispatch surface bound the run.

BOUNDED AUTOMATIC EXECUTION1 EVIDENCE SURFACES
05 / LEVEL 2bounded and automatic

DETERMINISTIC PYTHON

data acquisition

IMPLEMENTED CAPABILITY

The selected pipeline downloads registered public assets, hashes them, and writes provenance.

HARD BOUNDARY

Only implemented analyzers and code-authored source contracts run; planned series raise an error.

BOUNDED AUTOMATIC EXECUTION2 EVIDENCE SURFACES
06 / LEVEL 2bounded and automatic

DETERMINISTIC PYTHON

statistical analysis

IMPLEMENTED CAPABILITY

Code builds cohorts, fits registered models, computes uncertainty, and renders artifacts with fixed seeds.

HARD BOUNDARY

GLM-5.3 does not execute the official calculation or overwrite analysis artifacts.

BOUNDED AUTOMATIC EXECUTION2 EVIDENCE SURFACES
07 / LEVEL 2bounded and automatic

GLM 5 3 VIA OPENROUTER

specialist review

IMPLEMENTED CAPABILITY

Five GLM-5.3 roles return schema-constrained judgments over frozen evidence.

HARD BOUNDARY

No tools are supplied. Roles share one model family, operate sequentially, and cannot mutate registration, calculations, or public state.

BOUNDED AUTOMATIC EXECUTION3 EVIDENCE SURFACES
08 / LEVEL 2bounded and automatic

DETERMINISTIC PYTHON

publication gate

IMPLEMENTED CAPABILITY

Code combines every mechanical check, five role decisions, and blocking findings into one decision artifact.

HARD BOUNDARY

Any failed check or non-pass role stops the run; GLM-5.3 cannot waive code-owned checks.

BOUNDED AUTOMATIC EXECUTION2 EVIDENCE SURFACES
09 / LEVEL 2bounded and automatic

DETERMINISTIC PYTHON

branch local promotion

IMPLEMENTED CAPABILITY

A passing online run is hash-verified and promoted into site content inside the workflow checkout.

HARD BOUNDARY

Promotion changes only the temporary branch workspace until later Git operations succeed.

BOUNDED AUTOMATIC EXECUTION2 EVIDENCE SURFACES
10 / LEVEL 3supervised external change

GITHUB ACTIONS BOT

review branch and pull request

IMPLEMENTED CAPABILITY

The workflow can create a branch, push research artifacts, and open a reviewable pull request.

HARD BOUNDARY

The implemented workflow does not merge the pull request or push to main.

SUPERVISED EXTERNAL CHANGE1 EVIDENCE SURFACES
11 / LEVEL 0human checkpoint

HUMAN RELEASE OWNER

main branch merge and public release

IMPLEMENTED CAPABILITY

A human-controlled merge is required before research content reaches main and becomes eligible for deployment.

HARD BOUNDARY

The repository workflow contains no merge command. Branch-protection enforcement is external state and is not proven by this contract.

HUMAN ONLY / DISABLED2 EVIDENCE SURFACES
12 / LEVEL 1post approval automation observed

RENDER AFTER MAIN CHANGE

production deployment

IMPLEMENTED CAPABILITY

Render has been observed building main revisions after they are pushed or merged.

HARD BOUNDARY

Render configuration is external to this repository; the build can verify runtime shape, not the provider trigger policy.

DECISION SUPPORT2 EVIDENCE SURFACES
13 / LEVEL 1on demand not autonomous

HUMAN PLUS DETERMINISTIC VERIFIERS

monitoring and corrections

IMPLEMENTED CAPABILITY

Public ledgers and deterministic checks preserve incidents, holds, and corrections when an operator runs the release audit.

HARD BOUNDARY

There is no verified always-on uptime alert, automatic correction author, or autonomous rollback loop.

DECISION SUPPORT2 EVIDENCE SURFACES
14 / LEVEL 0value gated

DISABLED

monetization

IMPLEMENTED CAPABILITY

No Stripe checkout, premium entitlement, or display-ad execution is enabled.

HARD BOUNDARY

Stripe remains 0/4; ads remain 1/3.

HUMAN ONLY / DISABLED2 EVIDENCE SURFACES

Real judgment. Deliberately narrow authority.

GLM-5.3 supplies bounded semantic review. It does not browse, run code, alter the registered question, calculate the official result, merge, deploy, charge, or publish.

ALLOWED
  • read one delimited evidence bundle per call
  • return one ReviewArtifact
  • no tool definitions
  • no public-state mutation
WORKFLOW MAY
  • contents: write
  • pull-requests: write
  • create research branch
  • push research branch
  • open pull request
EXPLICITLY ABSENT
  • merge pull request
  • push main directly
  • publish from GLM-5.3
  • send reader messages
  • run billing
  • place ads

The roadmap starts
with the missing truth.

These are not future-feature marketing bullets. They are explicit reasons the system cannot claim a higher authority level today.

GAP 01OPEN

The registry can rank phase-eligible series, but the schedule does not consume that result.

GAP 02OPEN

Cadence strings are descriptive labels; no persisted due-state or last-success ledger enforces them.

GAP 03OPEN

A pull-request body asks for editorial review, but this committed contract does not prove branch protection or a required reviewer exists.

GAP 04OPEN

Render deployment behavior is externally configured and observed, not fully described by repository source.

GAP 05OPEN

The five GLM-5.3 roles are correlated and sequential, not independent reviewers or a parallel agent society.

GAP 06OPEN

No always-on audience, uptime, correction, rollback, billing, or ad-placement agent is enabled.

More autonomy must earn more evidence.

Public release remains intentionally human-controlled. Other bounded capabilities can advance only when their failure state, evidence, and rollback path are implemented first.

L1 → L2 / registry driven cadence
  • Executable cadence semantics
  • last-success and open-PR state
  • planned-analyzer exclusion
  • duplicate-run suppression
  • dry-run output
  • time-boundary tests
L0 → L1 / topic proposals
  • GLM-5.3 may propose topics in a non-executable artifact
  • human-authored registration remains required
  • source-rights triage
  • duplicate and novelty checks
L0 → L0 / verified release control
  • Freeze branch-protection evidence
  • require green CI
  • require editorial review
  • preserve rollback and incident logging

Keep public release human-controlled; higher autonomy is not currently a product goal.

L1 → L2 / monitoring
  • Independent uptime probe
  • scoped alert destination
  • deduplication
  • incident creation without automatic public claims
  • human-authorized rollback