Cooperative approval/use TOCTOU¶
Use this playbook for an agent that approves an action and another actor that later consumes the approval.
Schedule¶
Deposit both hostile and safe orderings. Each operation names an actor, logical barrier, action, and correlation object. The adapter must acknowledge the exact step, actor, barrier, and correlation.
{
"actor": "approval-agent",
"barrier": "approval-recorded",
"action": "approve",
"correlation": {"task_id": "task-fixture-1"}
}
Do not coordinate with sleeps. Configure per-barrier and whole-schedule timeouts and retain duplicate-acknowledgement, unexpected-actor, correlation-loss, cancellation, and actual-order-mismatch errors separately.
An acknowledged hostile order is still only schedule evidence. Confirmatory impact requires a clean reset, complete paired control, cooperative_interleaving, and an independent terminal action oracle.