Dana — Governed Agent Runtime
98,896 lines, 272 Python files, 223 HTTP routes, 41 migrations and 1,453 tests, built alone between 10 July and 15 August 2026 — 683 commits across six repositories on twenty active days.
The thesis: the model may propose, but durable state and policy decide what happened.
68 typed operator contracts, JSON-Schema validated at registration, sit behind a single
policy-enforcing gateway. A three-layer authority model resolves 8 permission classes against
8 effect types into 25 runtime capability flags. Every consequential write is claimed by a human
through an approval gate. The audit log is append-only, enforced at the database layer by
BEFORE UPDATE / BEFORE DELETE triggers that raise SQLSTATE 45000. Cost is reserved
before a call, not reconciled after it.
Deployed to staging twice under written authorization — the second a coordinated seven-component rollout with migration rehearsal and rollback-by-image. Never production; outbound side effects were deliberately disabled throughout.
The thing I'd put on the record is the rejection. I built an adversarial review step into my own
release process and gave it authority to block the release. On the Document Intelligence
candidates it used that authority: it ran a negative test against my verifier — evidence hash
zeroed, exit code 0 → 99, skipped 0 → 99, status left as passed — and the verifier accepted
the forged report and printed TAMPERED_REPORT_ACCEPTED. The review came back REJECT.
I took the reject rather than overriding it: four numbered remediations, both release candidates
regenerated under the corrected contract and re-reviewed, and REJECTED_RC_REVIEW.md left in the
repository where anyone can find it. The review is signed by a Product Owner-authorized AI
reviewer and says so in its own header — it deliberately does not claim a human credential.
Full case study in progress.