Recovery begins from local startup continuity and proves current runtime state before remote work resumes.
Failure states
Record service unavailable, service unreachable, unauthorized, stale coordinator epoch, expired process lease, unknown delivery, lost response, cursor gap, and revision conflict as distinct states.
Recovery order
- Load
.uai/startup-packet.uai, then the swarm root, roster, allocation, shared-state policy, recovery policy, and current receiver brief. - Verify the current runtime contract and authentication boundary.
- Read back coordinator epoch and process lease.
- Resume from each recipient cursor.
- Reconcile stable idempotency keys after lost responses.
- Preserve stale-parent and concurrent conflicts.
- Record current canonical proof before claiming delivery, acknowledgement, completion, durable write, or lease ownership.
Fail-closed behavior
If identity, authority, parent revision, lease, delivery state, or credential scope is unknown, stop the affected remote operation and request review. Local inspection and other independently authorized work may continue.
Support boundary
Agent runtimes execute. UAIX records portable configuration, logical identity, authority boundaries, routing references, reviewed evidence, and offline continuity. Runtime systems retain authentication, credential verification, leases, queues, transactions, tool execution, database writes, and delivery readback. A missing-authority request is review-pending only and applies no grants.
Schemas and validation
- Advanced Multi-Agent Workload schema
- Reference workload example
- UAI-1 profile registry
- Swarm Readiness checklist