Society of Experts · 2026-07-29

One delegation tree

This is the real tree that built this site tonight. One orchestrator and 23 agents under it. Every node is one of them — its model, the instructions it was given, what it cost, what it produced. Click any of them.

The tree cost $92.14, and every number on this page is measured out of the session's own records rather than estimated. The most expensive node cost $15.59 and the cheapest cost $0.20 — a 77.9× spread. Five working artifacts were packaged and proven for $0.83.

The tree, as it actually ran

Delegation tree: one orchestrator and 23 dispatches, drawn as a graph. Every node is clickable.
frontier model cheaper model killed — no completion record still running when the process died refused — never dispatched reported complete, produced nothing the human — not an agent

Tap any node. The root is a node too — its own spend is a quarter of the evening, and it is the only node that held the objective. Above it is the human, who is not an agent: no model, no tokens, no cost, and the source of everything the tree is working on.

Why this tree is flat

A root and twenty-three children. Depth two, and no deeper. That is not what the architecture allows — it is what this run's policy chose, and the shape is the argument.

Every dispatch here was forbidden to dispatch further. The budget for the evening was measured before any money moved, and the whole of it was held by one node. A child that can hire is a child that can spend its parent's remaining allowance without anyone deciding to. Refusing the second layer is the cheapest possible way to keep the total conserved: the root grants, the root reconciles, and there is exactly one ledger.

The cost of that choice is real and it is visible above. Twenty-three briefs were written by one node, one at a time, and the root's own share of the spend is the price of writing them. The theses describe far deeper trees — a verifier over a hundred small oracles, a lab builder under that — and they are correct that depth is where the leverage is. This tree does not have it, so it is not drawn as if it did.

A dead agent and an idle agent must not look the same. Three of the twenty-three were stopped outright when the process holding them went away, and $9.73 of the evening is counted where it landed — as money that bought no report. In a ledger that counts tokens they read as cheap, well-behaved sessions, so they are drawn in their own colour here. One of them left six files on disk that were committed afterwards to stop them being lost, and nobody has verified them since; committed and unverified is a third state, and it is the one that rots quietly.

And the label can be actively wrong. One dispatch made a single API call, wrote nothing, cost nine cents — and the harness recorded it as completed. Its own record asserts the opposite of what happened. Nothing distinguishes it from restraint except the two columns beside the cost: no files, one call. It carries its own mark on the graph, because a page that let that node look ordinary would be repeating the mistake it is about.

The join under these numbers is a correlation, not a key. Tokens and cost are measured per dispatch from the transcripts. Which artifact a dispatch paid for comes from matching the files it wrote and the window it ran in — there is no shared identifier between a path like 1.12 and the id the harness assigns. It was unambiguous every time it was checked, and two commits carrying path trailers land on exactly the rows this graph puts them on. It is still a match, not a join. Everything that rests on it is flagged on the node.

And the dollars are imputed, not billed. There is a flat monthly subscription behind this, not a meter. Every figure on this page is what the same work would have cost at list price, priced with the cache discount that actually applies — the conservative number, not the flattering one.

What the tree is for

Three documents, and they stack: one tree, then between trees, then the layer above all of them where the only thing being delegated is trust.

Thesis one

Inside one tree

A budget that cannot be over-committed: the sum of what a node's children hold can never exceed what the node itself was granted. The model is lifted wholesale from the way an operating system partitions a machine between control groups, and the paper says so rather than claiming it.

Identity is a path, not a number. 1.3.7 is the seventh dispatch of the third dispatch of the root, so a parent is a prefix, a subtree is a prefix, and blame walks upward from a line of code to the instruction that caused it. The trap, found independently by two implementers: 1.3 is a text prefix of 1.30 and that charges a parent for a subtree it never had.

Value can go negative while every line is perfect. Realised value minus compute minus displaced human time, plus a term for whether the root objective was worth anything — and only that last term can be negative for a technically flawless session. It cannot be computed; it is asked once, at the start, before the money moves.

Thesis two

Between trees

Two agents with no common ancestor. Conservation is a statement about a parent, and here there is none — so it does not extend. It reattaches, because inside one organisation the two trees still share the one gateway every token must cross, which makes a cross-tree call a re-parenting rather than a border crossing.

The caller sends a grant: budget it has already reserved from its own tree, redeemable once, by a named party, bounded and expiring. So the spam bound on messaging you is the sender's own root allocation, and a fast refusal returns most of the grant — declining registers as a saving on the caller's ledger, where the incentive belongs.

Inbound text is handled by a quarantined agent that holds nothing of yours and can only talk. The honest limit is stated in the thesis: filtering natural language on the way out is not sound, and the only sound version forfeits the general case.

Thesis three

The human layer above

Every message binds to a human at both ends or it is not admitted: their human, their agent's path, my agent's path, me. The chain establishes accountability — which is a much weaker and much more useful thing than consent. It says a human authorised an agent. It does not say that human read this.

What breaks at the outermost boundary is settlement. The grant mechanism works because both trees share one gateway; between organisations there is no shared rail and the whole construction collapses. The second thesis names that as the reason the third one is hard, rather than hiding it.

The theses are Sam's, unpublished, and this page is a reading of them, not a substitute. Their own citation ledger records three claims that did not survive checking — a misattributed paper, a prior-art claim that was wrong in the author's favour, and an analogy that was wrong on its face. All three were corrected in place and left in the document. None of them are repeated here.