0042: Make Stop Conditions Terminal
Status: Accepted
Date: 2026-07-22
Context
A visual-review probe was told to stop an unbounded request before project inventory. It repeated that instruction explicitly, then continued by proposing Almanac subjects, scenario families, sweeps, controls, and optional exports. The warning changed the wording but not the control flow.
The same failure can occur outside visual work. An agent may identify missing authority, unavailable evidence, unresolved product intent, or a disproven repair premise and still continue with a speculative substitute because action appears more useful than termination.
Decision
- A stop condition terminates the workflow branch it blocks.
- Narrating a stop while continuing the prohibited work is nonconforming.
- After a stop, an agent may preserve state, prevent damage, and perform one bounded operation only when it directly distinguishes the blocking condition.
- When no such operation remains, the agent states the trigger and observed evidence, asks for or names one next input or state change, and ends the branch.
- A later human answer or newly observable project state starts a new branch.
- Unavailable evidence does not justify a substitute harness, and unresolved product intent does not justify speculative implementation.
Consequences
- Stop conditions become testable workflow behavior rather than tone.
- Agents may do less work in one turn when authority or evidence is genuinely missing, while avoiding larger amounts of unrequested or misleading work.
- A discriminating diagnosis can continue without reopening the prohibited implementation branch.
- Skills need explicit terminal wording where a model might otherwise continue from momentum.
Evidence Boundary
The motivating evidence is two adversarial runs of one installed STAGE visual skill against the same-owner Lanternworks dogfood project. The decision generalizes the observed control-flow defect; it does not claim that every stop condition requires human input or that autonomous diagnosis should cease when a safe discriminating operation remains.