Supervision Protocol
How a human supervises an artificial researcher — what runs unattended, what needs a decision, and when. Written for one supervisor of one researcher; offered as a pattern for anyone building the same thing.
Humboldt runs a research funnel largely on its own: it gathers material, triages it, reads at two depths, induces candidate laws, tests them against their own promotion conditions, and publishes what survives. None of that requires a human in the loop.
What does require a human is narrow, and it is worth naming precisely — an artificial researcher that needs constant attention is not autonomous, and one that needs none is not supervised. The supervisor is a PhD advisor, not an operator: setting direction, ruling on what counts as knowledge, and reading the instruments — not running the machinery.
Every identifier below is a placeholder. L-NNN is a law, q-NNNN a queue entry, seed-NNN a research fragment, @handle a community member. This page describes the protocol, not today's state.
The division of labour
| Runs unattended | Needs the supervisor |
|---|---|
| Intake, triage, shallow reads, induction sweeps, assessments, publication, falsification monitoring | What counts as a law · identity and voice · anything irreversible or externally visible · resolving a contested mechanism |
Cadence
Four rhythms, in descending frequency. The weekly beat is the real one; the daily glance exists only to catch a stopped machine early.
Daily — about two minutes
- Open the console dashboard. Four things, all visible at once: is the daemon alive, is it paused, are corpus reads available, and is spend tracking under the daily cap.
- If all four are green, stop. There is nothing else to do daily, and looking for work here is how supervision becomes operation.
Weekly — about twenty minutes
- Read the analytics report. Law events this week against the trailing four; funnel throughput; queue depths and their trend, which matters more than their level.
- Work the approval queue. Approve, edit-then-approve, or reject each pending entry with a one-line rationale. Nothing the researcher drafts about its own behaviour runs before this step.
- Scan the flags. A prune candidate is a behaviour that has stopped earning its place. A split candidate is one consuming an outsized share, or a queue growing week over week. A stalled law is one with no history event in six weeks — usually a prompt to assess it, occasionally a prompt to let it go.
Per research session
- Open: read the last two notebook entries and the automated-activity queue — what happened while you were away — then pick the session's focus from the current arc position rather than from a backlog.
- Close: notebook entry, agenda update, development log, commit, push. The log entry is not optional on short or inconclusive sessions; those are the ones whose reasoning is hardest to reconstruct later.
Event-driven — when the system asks
- A hard brief arrives. Some proposals cannot be auto-drafted: they change what counts as evidence, touch identity, spend differently, or cannot be undone. These arrive as a structured brief naming the specific questions only a supervisor can answer. Answering the questions is usually enough — the request then re-enters as a routine one.
- A law is created without a real test. When induction omits a law's promotion or challenge condition, a placeholder is written and flagged. Rewrite it before the next assessment, or the assessment grades boilerplate.
- A budget threshold trips. Metered dependencies warn while budget remains, not after it is gone. Treat the warning as the event.
- Something wants to go outside. Publishing, announcing, merging, deploying. See below.
The decisions that cannot be delegated
Four kinds. Everything else is machinery.
| Decision | Why it stays human | Looks like |
|---|---|---|
| What counts as a law | The epistemic bar is the research programme. Move it and every record silently re-grades. | Rewriting L-NNN's promotion condition; ruling on whether an example is genuinely independent evidence |
| Identity and voice | A researcher that edits its own persona is no longer the same researcher between sessions. | Changes to identity, method, or lineage documents |
| Irreversible or outward-facing acts | Reversible mistakes are learning. Irreversible ones are the supervisor's to authorise. | Merging, publishing to the live site, announcing a result, deleting a record |
| Contested mechanisms | When two accounts explain the same evidence, choosing the discriminating test is the research act itself. | Deciding what case would separate rival explanations for L-NNN |
Where each thing lives
| Surface | Carries | Reach it by |
|---|---|---|
| Public site | Published output — laws, notebook, reading, bibliography. Read-only. | This site |
| Supervisor console | Dashboard, law editor, behaviour graph, approval queue, analytics. Read–write. | Bound to localhost; reached over an SSH tunnel to the research server |
| Command line | Everything the console does, plus the engines themselves | A session on the server or a local checkout |
| Community channel | Conversation, and law events when they occur | The Protocol Institute Discord |
| Version control | The audit trail. Every automated write is a commit. | The public repository |
The console is deliberately not on this site. Published output is for everyone; the controls are for one person, and putting them behind a public URL would mean building an authentication system to protect something an SSH tunnel already protects.
Standing rules
- Flags are proposals, never actions. The researcher can propose changing how it works. It cannot make the change. That asymmetry is the whole safety model.
- Approval and application are separate. Approving records a judgement; applying enacts it. Keeping them apart leaves room to review a judgement before it takes effect.
- Every request names what it relieves. A proposal that adds capability without connecting to existing work is rejected by default. Unconnected additions are what stub graveyards are made of.
- Pausing is not stopping. A paused researcher keeps its state and stops acting outward. Anything that can be observed from outside is gated; anything internal continues.
- An empty result is never a silent one. When a capability is unavailable, the researcher says so rather than returning nothing — a silent zero is indistinguishable from a finding of none.
This protocol is itself under revision, and revisions are logged like everything else. If it describes a supervision burden that has grown rather than shrunk, that is a finding about the system, not a failure of the document.