Agent agreement is not application truth
A multi-agent system often looks impressive because several named specialists exchange messages: a researcher finds evidence, a planner proposes steps, a critic identifies risk, and a reviewer approves the result. That structure can improve coverage and make responsibilities easier to inspect. It can also hide the same authority mistake behind more voices. Agents are still generative or learned components. Their messages are observations, interpretations, and proposals. They do not become facts, permissions, or completed actions because another agent responded “approved.”
The distinction becomes obvious when the system acts around people or shared operational state. A preference agent may remember that someone likes jazz. A venue agent may find a current public event. A social planner may rank the event highly. None of those agents owns the other person’s consent, contact eligibility, or private context. Likewise, three learning agents may agree that a user appears comfortable with deterministic authority. They cannot award mastery without verified evidence. An operations team of agents may agree to create an incident, but an existing idempotency key and authoritative incident record can still prove that the proposed action would be a duplicate.
Agents can negotiate a proposal. They cannot negotiate reality into existence.
What the world authority owns
The world authority is not necessarily one database table or one centralized service. It is the declared set of exact owners for the state that must not be decided through language. It defines canonical identities, accepted versions, current consent, permitted disclosure, verified progress, protected meaning, authoritative world frames, incident identity, action approvals, and external postconditions. Different fields may have different owners, but each field has one deterministic admission rule.
That architecture prevents a global “super-agent” from becoming a hidden source of truth. An event source owns public event facts. A user owns current social intent and revocable consent. Source-reviewed doctrine owns canonical definitions. A deterministic chart engine owns calculated placements. A document revision and reviewer own accepted text. An operational system of record owns the current incident. The multi-agent layer can combine those facts and propose a next step, but the exact owner decides what can change.
Put multi-agent cooperation on top of the complete intelligence spine
R10K does not create a second orchestration philosophy. Every agent observation enters the same OverLift spine used by the main demo and Learning Center: governed input, T0 ground, CATS C0–C7 route selection, Tier-S challenge, T0–T7 execution or proof, Semantic Bridge, Q-Lens, deterministic fusion, authority projection, compiler, receipts, and exact replay. The agent layer adds identity, grants, world versions, proposal admission, conflict resolution, idempotency, and postconditions.
This layering matters. Semantic retrieval can help an agent find the right doctrine, but it cannot publish that doctrine. Q-Lens can compare several social plans, but a probability cannot grant consent. A causal agent can explore why a shipment is at risk, but it cannot rewrite a source record or claim a hold succeeded. Tier-S challenges both the selected reasoning path and the complete proposed result before world authority sees it.
Capabilities are typed, bounded, revocable, and non-transitive
An agent receives only the capabilities required for its assigned role. A venue agent can read public venue facts and explain accessibility. It cannot read private dating notes. A consent verifier can inspect current scoped consent and block contact. It cannot manufacture consent or send the message itself. A doctrine agent can publish a reviewed definition after source and lifecycle checks. It cannot mark a learner mastered. A delivery recovery agent can verify a postcondition and propose rollback. It cannot claim success because an API returned an ambiguous timeout.
Delegation does not automatically transfer every permission. When one agent asks another to perform work, the delegated packet carries the caller, grantee, capability, resource scope, time limit, world version, evidence identities, and expected response. The receiving agent cannot widen the scope, forward the grant invisibly, or convert a read capability into a write. Expired, stale, duplicated, or mismatched grants fail closed.
Conflict resolution is deterministic; consensus is bounded
Agents can disagree because they saw different sources, different times, or different responsibilities. The system should materialize the disagreement rather than average it into smooth prose. If a retrieval agent proposes a retired definition and a lifecycle agent supplies the current reviewed definition, canonical-doctrine authority decides. If a style editor proposes a fluent rewrite that changes $425,000 to $452,000, protected-meaning authority rejects it. If a predictor operates on frame 438 while the world is at frame 440, exact world-version authority rejects the stale proposal.
Some conflicts have no deterministic owner or enough evidence. In those cases the correct outcome is clarification, hold, escalation, or abstention. Consensus algorithms are useful when the product truly requires distributed agreement over replicated authoritative state. They should not be used as a rhetorical device for turning several model opinions into truth.
Veluris: event, venue, preference, safety, and consent agents under human authority
Veluris benefits from specialization. Public-event agents can acquire and reconcile event records. Venue agents can understand accessibility, noise, travel, and public/private characteristics. Preference and intent agents can use only explicit or permitted context. Safety agents can identify missing age, location, travel, or disclosure evidence. Consent agents can verify whether a specific introduction or contact channel is currently authorized. Explanation agents can show why a public plan was suggested and what remains unknown.
The world authority keeps discovery, recommendation, drafting, introduction, disclosure, contact, sending, and relationship choice separate. A remembered preference can support a private plan comparison. It cannot create mutual consent. An agent may prepare an unsent draft or recommend requesting permission. It may not reveal private context, contact another person, or declare compatibility as fact. Human choice remains the final authority over whether any relationship begins or continues.
This is not a limitation on intelligence. It is what allows Veluris to become more intelligent without becoming entitled. The system can understand more context, compare more respectful options, explain uncertainty better, and abstain sooner while retaining hard boundaries around another person’s autonomy.
The Learning Center: cooperating teachers without mutable doctrine
The Agentic AI Glossary & Learning Center can use agents for canonical retrieval, misconception detection, prerequisite analysis, lifecycle checking, explanation planning, learning-path comparison, progress review, and evaluation. Each specialist improves a different part of the learning experience. The doctrine agent preserves canonical identity and source status. The misconception agent identifies a likely category error. The prerequisite agent proposes what should come first. The explanation planner adapts examples and depth. The evaluation agent checks demonstrated understanding.
Those agents do not share one unrestricted memory or one authority level. Private learner state remains local and user-controlled. Canonical doctrine is source-reviewed. Lifecycle status is temporal evidence. Verified mastery requires declared assessment evidence. Viewing, liking, repeating, or finishing navigation is not mastery. When agents disagree, the Learning Center can show the alternatives and ask a clarifying question rather than quietly selecting the most flattering interpretation.
Operations require idempotency, concurrency, and exact identity
Operational multi-agent systems fail in ordinary ways: a timeout triggers a retry, two agents create the same ticket, a plan was based on a stale record, or a delayed response arrives after state changed. Typed action adapters therefore require an idempotency key, observed version, exact target identity, caller and approval identity, bounded payload, and expected postcondition. A retry with the same key returns the existing result instead of creating another effect. A stale version fails rather than overwriting newer state.
In Logistics, an investigation agent may correlate shipment, sensor, customs, and policy evidence. An incident agent may propose updating the existing incident. A risk agent may propose a contained hold. The deterministic compiler checks whether the incident already exists, which approval is required, whether the proposal still matches the current shipment version, and whether the postcondition occurred. The agents can improve diagnosis and planning; they cannot make the external system pretend the action succeeded.
Success belongs to verified postconditions, not agent narration
An agent saying “done” is not a postcondition. The application must verify the external result through the system that owns it. Did the incident actually update? Did the deployment route return the expected release identity? Did the message remain unsent? Did the document revision preserve protected claims? Did the new doctrine pack activate with the expected hash? If verification fails or remains ambiguous, the state is failed, pending, or recovery-required—not successful.
Recovery uses the same exact identities: action key, previous state, attempted transition, observed result, rollback target, and receipt. The product can retry safely, return the existing result, quarantine the candidate, restore a known-good state, or ask a human. It must not conceal the failure behind a confident summary.
Evaluate cooperation, authority, and recovery—not just the final answer
A multi-agent evaluation set should measure more than whether the final text sounds useful. It should include source containment, correct agent selection, capability violations, stale-world rejection, duplicate-action prevention, consent and disclosure errors, doctrine mutation, false mastery, protected-meaning drift, unresolved conflicts, unnecessary delegation, trajectory length, latency, memory, postcondition accuracy, rollback, and exact replay.
Hard cases matter most: a socially attractive plan without consent, a semantically similar retired standard, a duplicate operational ticket, a late real-time prediction, a document edit that changes a number, a new filing that should create a new conclusion, and an external timeout with an unverified result. A system that succeeds only when all agents agree has not earned world authority.
Honest limits
The R10K laboratory is deterministic and same-origin. It does not contact real agents, people, event providers, enterprise systems, or deployment endpoints. It does not prove independent dating safety, educational effectiveness, production distributed consensus, or real-world operational correctness. Those remain owner, user, professional, security, and production gates.