SYNTHESIS NOTE
Topics›Agents Multi Architecture›this note

Who decides which agent communications get anchored?

The paper commits to anchoring 'selected' communications but never specifies who makes that selection, by what criteria, or how missed selections would be detected. This matters because the selector controls what evidence can ever exist.

Synthesis note · 2026-09-23 · sourced from Agents Multi Architecture

Two words carry the design. The abstract anchors commitments for "selected agent communications," and the conclusion speaks of "critical process traces." The GRC list adds "risk-based evidence selection" as a practice. Anchoring everything is presumably not the goal, since cost and privacy would both object. That is my reading, and the excerpt does not say why the selection is there.

If selection is by design, then selection is itself a control. Whatever is not selected has no anchor and can never later be shown unmodified. So the open questions are about the selector. Who chooses: a compliance function, the platform, the agents themselves? By what risk criteria? Fixed in advance or adaptive? And how is a miss detected, given that a missed trace leaves no anchor to notice its absence? The evidence model's "authorized anchoring" (What can a blockchain anchor actually prove about records?) asks who may anchor, and selection asks who decides what is worth anchoring. The excerpt does not say whether these are one control or two.

A risk-based selector predicts what will matter. The incident the paper cites as motivation reportedly involved traffic through unauthorized channels (Can a black box see communication through unauthorized channels?), which is the kind of traffic an expectation-based selector is least likely to list. This is a worry and not a finding, since the excerpt does not describe the selection method at all.

Two neighbours in the vault bear on the selector, both from other settings and neither on this paper. What to keep depends on which actions belong together, and Can defenders discover agent episodes without knowing membership in advance? asks how to find that grouping before anyone hands it over. Can a finite lifecycle model detect reward hacking across benchmarks? writes down what to record as a finite typed lifecycle of reward-relevant events. My reading is that such a rule can be enumerated because a benchmark's reward path is closed, and the excerpt does not say who writes a binding. Whether an open agent workflow has a comparable finite model is addressed by neither excerpt.

The vault also holds one device for making a control's silent miss visible: the fourth move in Can deterministic checks protect LLM judges from failure? plants a known case and treats its failure to register as the alarm. Applied to a selector it would mean planting a known communication and checking that it gets anchored. That transfer is my suggestion and the black-box excerpt proposes nothing like it. It would test the selector only on what someone thought to plant, which is the coverage limit the vault records for planted cases, and the traffic an expectation-based selector is least likely to list is the traffic least likely to be planted.

A usable test for anyone writing about the layer: before saying it "would have shown" something, ask whether that something would have been selected.

Inquiring lines that read this note 7

This note is a source for these research framings, grouped by the broader line of inquiry each explores. Scan the bold lines of inquiry; follow any specific question forward.

How do agents balance task completion with privacy compliance and security? What infrastructure evidence validates agent benchmark achievement claims? How does misaligned communication propagate bias through multi-agent networks? How can we verify agent claims against their actual capabilities and actions?

Related concepts in this collection 6

This note in its neighbourhood — explore the map, then jump to a related concept in the list below.

Concept map
16 direct connections · 116 in 2-hop network ·medium cluster Open in graph ↗

Click a node to walk · click center to open · click Open in graph to see this note in the full knowledge graph

your link semantically near linked from elsewhere

Related papers in this collection 8

Papers most semantically related to this note, ranked by cosine similarity in the embedding space.

Original note title

how is it decided which agent communications get anchored — the architecture anchors selected traces and the GRC discussion names risk-based evidence selection but the excerpt does not say how selection is made or checked