Glass Ionomer: An Evidence-Governed Control Architecture for Language-Model Agents

Agentic systems combine generative reasoning with access to tools, mutable environments and software revision. Their assurance problem extends beyond whether a model produces a plausible answer: evidence, permission, execution and the authority to change the governing mechanisms must remain distinct. Glass Ionomer confines the proposer to an enumerated proposal channel and leased workspace, assigns status minting to a deterministic assurance kernel, and places execution credentials and authoritative history beyond the proposer's credentials, administration and recovery access. Seven coupled loops govern inquiry, consequences, training, setpoints, coverage, controller integrity and construction. Permanent global attempt lineage retains claim-shopping attempts as evidence across principals; an unavailable multiplicity classifier invokes the prescribed CONTESTED cap. Effects require externally durable intent, exact authorization and object binding. Uncertain execution remains UNKNOWN until reconciliation; anchor unavailability triggers a latched alarm and bounded visible halt. Authority-document changes require complete machine-diff classification and independent cold review. We evaluate these controls with an executable architectural model: 5,708 deterministic scenario checks spanning twenty acceptance families, twelve deliberate control mutations (all detected), bounded exploration of 1,965 states and 7,453 changing edges across six configurations, and 1,200 seeded fault sequences containing 72,000 event inputs (no checked invariant violations). Seven separately reported probes expose trust-boundary consequences and implementation obligations, including denial-log saturation, semantic supersession and classification correctness. The contribution is a unified, externally anchored control architecture — governed self-modification with permanent cross-principal lineage, durable uncertain execution and classified revision — with a reproducible adversarial evaluation that makes its own boundaries explicit. Files (SHA-256)Glass_Ionomer_Elnaggar_2026_corrected.pdf — a3275556b39756d47cf649ec1031b9ca59ed4c113f8107e5467a48806d868025Glass_Ionomer_Supplementary_Change_Record.pdf — 7cf8257d03e485ccb6afe2da103089317f5d7837cc7c83fbdaf75229fbe465a7

Authors

Publication Details

Journal
Zenodo (CERN European Organization for Nuclear Research)
Published
2026-10-06
DOI
https://doi.org/10.5281/zenodo.23193669
Primary Topic
Access Control and Trust
Type
preprint
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
OCT
preprint

Glass Ionomer: An Evidence-Governed Control Architecture for Language-Model Agents

Amr Elnaggar
Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
preprint

Glass Ionomer: An Evidence-Governed Control Architecture for Language-Model Agents

Amr Elnaggar
preprint en

Abstract

Agentic systems combine generative reasoning with access to tools, mutable environments and software revision. Their assurance problem extends beyond whether a model produces a plausible answer: evidence, permission, execution and the authority to change the governing mechanisms must remain distinct. Glass Ionomer confines the proposer to an enumerated proposal channel and leased workspace, assigns status minting to a deterministic assurance kernel, and places execution credentials and authoritative history beyond the proposer's credentials, administration and recovery access. Seven coupled loops govern inquiry, consequences, training, setpoints, coverage, controller integrity and construction. Permanent global attempt lineage retains claim-shopping attempts as evidence across principals; an unavailable multiplicity classifier invokes the prescribed CONTESTED cap. Effects require externally durable intent, exact authorization and object binding. Uncertain execution remains UNKNOWN until reconciliation; anchor unavailability triggers a latched alarm and bounded visible halt. Authority-document changes require complete machine-diff classification and independent cold review. We evaluate these controls with an executable architectural model: 5,708 deterministic scenario checks spanning twenty acceptance families, twelve deliberate control mutations (all detected), bounded exploration of 1,965 states and 7,453 changing edges across six configurations, and 1,200 seeded fault sequences containing 72,000 event inputs (no checked invariant violations). Seven separately reported probes expose trust-boundary consequences and implementation obligations, including denial-log saturation, semantic supersession and classification correctness. The contribution is a unified, externally anchored control architecture — governed self-modification with permanent cross-principal lineage, durable uncertain execution and classified revision — with a reproducible adversarial evaluation that makes its own boundaries explicit. Files (SHA-256)Glass_Ionomer_Elnaggar_2026_corrected.pdf — a3275556b39756d47cf649ec1031b9ca59ed4c113f8107e5467a48806d868025Glass_Ionomer_Supplementary_Change_Record.pdf — 7cf8257d03e485ccb6afe2da103089317f5d7837cc7c83fbdaf75229fbe465a7

Zenodo (CERN European Organization for Nuclear Research)
Access Control and Trust
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.