the company cannot live in a chat summary

Every organization must distinguish what someone proposed from what it accepted, what an agent prepared from what an authorized person approved, what was sent from what was received, and what a system calculated from what a counterparty settled. Those distinctions are operational, not philosophical decoration. Money, liability and trust attach to them.

The Backoffice Institutional Kernel paper proposes six root families: Scope, Subject, Statement, Procedure, Episode and Artifact, connected by typed relations. An append-only journal preserves accepted transitions; authorization gates determine what may happen; runtime machinery executes procedures without becoming the source of truth. The human frontier is the work still requiring legitimacy-bearing judgment.

The proposal came through an April 2026 research collaboration with GPT, then became a paper draft and an accepted architecture RFC for Backoffice v3. Its theorem section is a program for mechanization, not a report that the entire ontology was proved.

There is a related but distinct research line called I-7. It asks how standards, protocols, a commercial operator and a reference runtime can hold legitimate institutional authority as governance matures. Seven ports describe products, stages, authority classes, fees, bonds, councils and forbidden interfaces. It should be read alongside the Backoffice paper, not fused into it.

a small number of things must mean different things

A support agent drafts a refund. A manager approves it. A payment service accepts the instruction. A bank settles it. A customer sees the money. There may be five records and one story people tell about them: “we refunded the customer.” The story becomes safe to use only when the organization can say which event it means. This is the problem the Institutional Kernel attacks.

The six root families are deliberately plain. A Scope is the boundary in which something is true or allowed. A Subject is the actor or thing concerned. A Statement is a claim the organization may need to accept, reject or revise. A Procedure tells a role how to act. An Episode is an occurrence with a beginning and end. An Artifact is the durable thing that carries content or evidence. Typed relations connect them. A refund approval can then refer to the order, the approving subject, the authorized scope, the procedure in force and the payment episode it permits. Without those links, the company has a document pile.

An append-only journal matters because institutional history should not rewrite itself when today’s interpretation changes. A correction can supersede an earlier statement while retaining the fact that the earlier statement existed and shaped a decision. This is not a demand for perfect memory. It is a way to make consequential revisions legible.

the human frontier is a design surface

Automation is often described as the removal of humans from a workflow. That framing misses the hard work: deciding where a human has legitimate authority and how to use their attention well. A manager should not manually confirm every safe, routine step. Nor should an agent infer permission to make a new commercial promise because a similar promise appeared in an old chat. The kernel’s authority model should carry that distinction into the tools agents use.

A good escalation arrives with the current state, the available moves, the likely cost of each, and the missing fact that could change the choice. It should also say who owns the decision. If the organization cannot answer that, “human in the loop” is a decorative phrase. It names a person without giving them the world they need to judge.

legitimacy grows beyond the company

The I-7 line looks at a further problem. A standard, a protocol, a commercial operator and a runtime may begin under one steward, then acquire participants whose interests diverge. Who can set fees? Who can change the rules? Which powers belong to a council, an operator or an implementer? The seven ports make those powers discussable before an implementation buries them in code.

For a business owner, the lesson is immediate even if the formal work is unfinished: write down what counts as an accepted fact, who may change it, and what outside event can overrule the company. You can start with one expensive workflow. If people argue over whether an item was proposed, approved, executed or settled, you have found a place where an institutional kernel would pay for itself.

a registry is not an institution

Many companies already have a CRM, a ticket system, a document store and a finance ledger. Each system knows some part of reality. None automatically knows what the company accepts as a whole. A CRM can say a deal is closed while the contract is unsigned. A ticket can say an issue is resolved while the refund is pending. The kernel’s job is not to replace those systems. It is to let claims and authority move between them without losing their meaning.

That is why the root families are more useful than another universal table of “events.” A Statement can be a claim about an external record. An Episode can show an agent attempted a procedure. An Artifact can hold the accepted document. The typed relations say which scope and actor each belongs to. An integration can then report an observation without awarding itself the authority to declare the business outcome.

The research is also a warning against treating schema design as a one-time taxonomy exercise. The categories matter because they constrain what future actors can infer. If a “statement” field can quietly carry an approval, the boundary has failed. If a procedure cannot say which actor may execute it, the organization is asking the runtime to guess.