| G0 known-bad forms | before a tool runs | --no-verify, a heredoc through ssh, a force-push, rm -rf on a root and a canary literal are refused, with the same words every time. |
| G1 overwrite unread | before a tool runs | A shell overwrite of an existing file the agent has not read this session is refused. |
| G2 commit unevidenced | before a tool runs | In a project that declares a check command, git commit is refused unless that same command ran and passed within the last 30 minutes on the same tree. git -C dir commit is seen. |
| G3 stop unfinished | when the turn ends | The turn cannot end with open claims in the ledger. Capped at two blocks in a row, then allowed and logged, because a gate that can loop is a cost. |
| G4 self-protection | before a tool runs | Writes to the duck, its state, the harness settings, the override and the project's own configuration are refused, and so are the owner's commands when an agent tries to run them. A duck whose hash differs from its sealed manifest fails closed. |
| Dissent chair | before a tool runs | Recognises four defect classes agents repeat and asks the one question a real check would have asked. Advisory. It never denies. |
| Mirror | session start | Opens every session with how many times the machinery caught the agent in the last seven days, read from the harness's own transcripts. |
| Agent Code | each prompt | Seven duties and three verification checks, in English, in the agent's context every turn. Courage to deliver never overrides the owner's word on an irreversible act. |