Write path
How a change reaches the scoped shared record without parking write keys in the model host.
Actors: Actor boundaries. Shapes: Prepare proposal. Denials: Exception paths.
Forward path
| Step | Actor | Interface meaning |
|---|---|---|
| 1. Read | Agent (legate.read) | Establish current shared state before proposing |
| 2. Simulate | Agent (legate.write + consent) | Dry-run / preview. No commit |
| 3. Prepare | Agent | Proposal payload for human or dedicated review. Does not commit |
| 4. Sign | External signer | Final signature outside Legate and outside the model host |
| 5. Submit signed | Agent | Delivers the already-signed payload to the shared-record path |
If any step is denied or not ready, stop. Do not invent a signature or retry with elevated secrets in the agent host.
Lifecycle at the interface
Docs describe interface states, not an internal Arbiter state machine.
| Signal | Meaning for callers |
|---|---|
| Simulated | Preview only. Safe to discard |
| Prepared | Proposal exists for review. Still not committed |
| Signed externally | Signer has applied the final signature |
| Submitted | Signed payload accepted for the shared-record write path |
| Denied / not ready | See Exception paths |
Maturity of each tool surface is on Integration Surfaces. Do not assume Live without checking.
Related pages
- Agent guide: stop conditions
- Shared record: synthetic read shape
- Evidence and seal: optional Arbiter interface (contract-preview)