Booklet · Version 2.0 · October 2026
RTSAXReal-Time Society, Architecture and Execution
Architecture for the Human–Synthetic Enterprise
A design hypothesis for the enterprise in which people and synthetic actors act on behalf of the same organization, under one governance architecture.
Intelligence provides capability. It does not confer a mandate.
The vision
Governance has to move into the moment of action
AI is developing faster than organizations can absorb it. The limiting factor is less and less the intelligence of the model, and more and more the enterprise's ability to let that intelligence act with meaning, with mandate and with effect.
Agentic AI can interpret context, weigh alternatives, choose next steps, use tools and initiate actions on its own. RTSAX calls a system that is given such room to act a synthetic actor. That does not mean AI becomes human or conscious. It means the system can act on behalf of the enterprise, and it creates a fundamental distinction between what a system can do and what it may do. A more powerful model expands capability almost immediately. Mandate should change only when the enterprise deliberately decides so.
Traditional governance works before and after the action: policies and procedures beforehand, quality assurance, compliance and audit afterwards. That becomes insufficient when synthetic actors act at scale and at machine speed. Governance therefore has to operate during execution, while people retain the understanding and means to direct and intervene.
As intelligence becomes more abundant, organizational scarcity shifts to meaning, mandate, execution and responsibility. The relevant chain becomes:
- meaning
- mandate
- decision
- execution
- evidence
- learning
RTSAX separates interpretation from authority. A system can understand perfectly what is happening without thereby acquiring the right to act.
Intelligence proposes. Authority permits. Mandate bounds. Execution acts. Evidence proves. The canonical formula of the architecture
Rhythm
The cadence at which a system observes, decides, acts and learns. Speed is not rhythm: an agent at machine speed can revise a decision a thousand times between two weekly reviews, so rhythm can no longer be left to habit.
Is this the right time and pace?
Norms
The agreements about what is permitted, required and forbidden. An agent has no moral compass of its own, so norms must be present at the moment of action, not only in rules beforehand or in liability afterwards.
Can this action be justified within the norms that apply?
Semantics
The shared meaning that lets people and systems understand the same words in the same way. An agent does not merely use language; it converts language into action.
Do all parties, human and machine, mean the same thing by the words they use?
The RNS triad: the three load-bearing functions of any stable order, whether a society, an organization or a technical system. AI puts all three under pressure at once. Of the three, rhythm is the most neglected.
The whole
Why, how and what: RTS, RTA and RTX
One architecture read three ways. The society-level vision explains why a reordering is needed; the runtime architecture shows how an enterprise becomes governable; the execution paradigm shows what happens in practice.
Rhythm, norms and semantics as the three load-bearing functions. Meaning is the new scarce capability, and the human role shifts from positional authority to semantic direction.
Four runtime layers in a closed control loop, eight layers of capability, mandate as a first-class object, CoreSOS and IMUS, Pulse and Pendula.
The architecture at work: every action authorized first, bounded and traceable. Configurations for enterprise, government, education, health and civil society.
The runtime core: four layers, one closed loop
Every action, by a human or by a synthetic actor, passes through all four layers, so that questions organizations usually answer implicitly are answered explicitly, at the moment of action. What the last layer establishes about one action returns to the first as state for the next.
What is happening, in what context and with what relevant information? Data is not state: state is the current, decision-ready picture built from scattered data.
What is permitted to happen, by whom and within what limits? Legitimacy is applied at the decision gate, which every action must pass.
What can be shown to have happened? This layer provides evidence and traceability for every action.
What actually happens? This layer executes, in bounded steps, what RTA2 has permitted. It does not decide.
The Runtime Control Loop
- Observe
- Evaluate
- Authorize
- Act
- Verify
Each cycle ends in one of four states:
- Continue
- Constrain
- Escalate
- Terminate
The boundary that matters most lies between Evaluate and Authorize. Interpretation is not authorization: observing and evaluating can become ever more intelligent, and no gain in intelligence creates authority. An agent that concludes that a customer deserves a refund has made a proposal, not a decision.
Eight layers of intelligent collaboration
The four RTA layers state which questions every action must answer. Eight functional layers supply the capabilities that answer them. They are a thinking model, not a fixed sequence, and none of the eight authorizes.
- PerceptionThe senses. Takes in signals and passes them on with their source.
- CortexThe interpreter. Translates signals into meaning, composes context, constructs options.
- CodexThe memory. The versioned vocabulary, definitions, decisions, precedents and rules.
- CuratorThe inspector. Checks quality and consistency, detects drift, recommends.
- PocketThe capacity manager. Tracks resources and enforces budgets with an escalation attached.
- OperatorThe executor. Where decisions become actions, and mandate is enforced most directly.
- MeshThe connection. Carries meaning coherently between Corpora and to external parties.
- LoopThe feedback and learning layer. Compares outcomes with intentions and returns proposed updates.
The Human–Synthetic Enterprise
Seven things an enterprise has to design
The Human–Synthetic Enterprise is the enterprise in which human and synthetic actors act on behalf of the same organization under one governance architecture. It is not a human organization with ever more AI tools added, and it needs no second governance system for AI. Mandate becomes the primary building block.
- IEnterprise ConstitutionOn what ground may anyone, human or synthetic, act on the enterprise's behalf?
- IIMandate and Decision-Rights ArchitectureWho may act, on whose behalf, within which limits and with how much discretion?
- IIIHuman–Synthetic Operating ModelHow do constitution and mandate become the actual organization of work?
- IVHuman–Synthetic Workforce ArchitectureWho should do a piece of work, in which combination of human and synthetic capacity, and who answers for it?
- VSemantic and Context ArchitectureDo those who act in the enterprise's name understand a situation, and the words that describe it, alike?
- VIRuntime Governance and Evidence ArchitectureWhat is an actor permitted to do before it acts, who decided that, and can it be demonstrated?
- VIILearning and Constitutional Evolution ArchitectureHow does the enterprise change without letting learning silently rewrite what it is?
One whole, from constitution to evidence, and learning as the way back. These are not seven software products. They are seven enterprise design responsibilities: platforms can supply more and more of the technical infrastructure, but the enterprise remains responsible for its meaning, its design and its limits.
Key ideas
The vocabulary of a governable enterprise
Eight concepts that carry most of the argument. The booklet's glossary defines the full set.
Synthetic actor
A non-human entity that observes, interprets and acts within human systems, with consequences for which people remain accountable. Agency is assigned, not assumed: what makes a system an agent is not its intelligence; it is its mandate. The interface may smile. The mandate must not.
Mandate
The explicit specification of what an actor, human or synthetic, is authorized to do. Every mandate has three parts: scope, conditions and escalation. An API token is not a mandate. If the three parts cannot be stated, the agent should not be deployed.
Action Authorization Decision
For every proposed action the authority function returns one of four outcomes: ALLOW, ALLOW WITH CONDITIONS, DEFER to a human, or DENY. Autonomy is graded on five levels, from observation to bounded autonomy, per category of action rather than per actor.
Trias Agentica
The powers to propose, to authorize and to verify are separated, so that no actor, human or synthetic, proposes, authorizes and verifies the same action. Execution Finality adds that authority must still be valid at the moment the action takes effect.
CoreSOS and IMUS
Two normative layers hold the norms in a form the runtime can consult. CoreSOS carries the organization's own principles, priorities and resolution rules. IMUS is a deliberately small set of universal, non-negotiable commitments that always takes precedence. Which principles bind the organization is never for AI to decide.
Pulse and Pendula
The Pulse is the agreed cadence at which the enterprise re-assesses its state against its norms, goals and environment. Pendula are deliberate counter-movements against over-correction, drift and fragility: deliberate slowness or deliberate deviation. The aim is not maximum speed but responsible speed.
Evidence
For every material action the enterprise must be able to answer four questions: who acted, on whose authority, under what mandate, and what actually happened. A Decision Record, an Execution Record and an Evidence Bundle carry the answers, built during operation, not after an incident.
Autonomy may be delegated. Sovereignty may not.
Four powers stay with humans, whatever becomes technically possible: changing the fundamental premises; granting, bounding and revoking mandates; resolving normative conflicts the normative layers cannot settle; and passing final judgment on the legitimacy of what was done.
In sum
Four propositions
What the booklet has tried to say, in four statements.
- Rhythm is a governance variable.
Most frameworks treat governance as a static set of constraints. RTSAX treats it as a living cadence that has to be designed, with a named owner.
- Where normative reasoning lives is a positional choice.
For platform vendors it is right to keep it outside the system. For organizations that operate close to their own decisions it is right to bring it inside.
- Measurement comes before architecture.
Build the measurement infrastructure before choosing the architecture, because the value of an architecture cannot be assessed without it. Its absence is one of the principal reasons most agentic-AI investments produce no measurable return.
- Mandate comes before capability.
No actor may act beyond its mandate. A better model enlarges what an agent can do, not what it may do. Capability expansion is not mandate expansion.
The honest position is that RTSAX is a design hypothesis, not yet validated. It is being applied, and the collection of evidence is at an early stage. It is offered as a working hypothesis rather than a finished prescription, open to correction, to disagreement and to the empirical test it should be held to.
From pilot to operating model
Start with one decision
Many organizations understand that AI needs governance and still fail, because they try to solve everything at once. A mandate architecture does not begin with a platform. It begins with one decision, and grows through repetition, not speed.
- 1Choose one real decision moment
A refund, a moderation decision, a customer answer: a case where it is clear what happens, who is involved and what the risk is.
- 2Make the mandate explicit
Deliberately simple: what is permitted, what is not, and what happens in case of doubt.
- 3Enforce it
The action passes the decision gate before it proceeds. The system changes from an advice machine into a controlled system.
- 4Organize escalation as part of the process
Not as an exception. Many early decisions escalate; without enough Steward capacity the system breaks.
- 5Record everything
Not only the outcome of each decision but why it was taken, in which context and under which rule.
- 6Learn and adapt
Where the system does not fit, humans adjust the mandate. The system grows through better bounding, not through new technology.
Measure first, then design deliberately, and only then scale autonomy. AI may never grow faster than its governance.
The booklet
Download the booklet
The compact edition of the argument: the executive summary, the four chapters and the annexes, in 76 pages. Free to download and read. The full argument is in the book RTSAX – The Architecture of the Human–Synthetic Enterprise (second edition, October 2026).
- Title
- RTSAX – Real-Time Society, Architecture and Execution. Architecture for the Human–Synthetic Enterprise
- Author
- Otto Th.G. van Haaren
- Edition
- Booklet, version 2.0, October 2026. Version 1.0 appeared in September 2025.
- Format
- PDF, 76 pages, 2.2 MB, English
van Haaren, Otto Th.G. (2026). RTSAX – Real-Time Society, Architecture and Execution: Architecture for the Human–Synthetic Enterprise. Booklet, version 2.0, October 2026. www.ottovanhaaren.com
© Otto Th.G. van Haaren. Reuse or distribution is permitted only with the express written consent of the author. Excerpts may be quoted with proper source attribution.
What's inside
- —Preface: One Year On
- —Executive Summary
- 1RTS – Real-Time Society (Why?)
- 2RTA – Real-Time Architecture (How?)
- 3The Human–Synthetic Enterprise: seven deliverables (What must an organization put in place?)
- 4RTX – Real-Time Execution (What?), with a refund request followed through the whole chain
- A1Glossary of terms
- A2Layered normativity: ten levels, from universal to individual
- A3What has changed since version 1.0
- A4Literature
What changed since version 1.0
- The whole is now called RTSAX; RTS is the Why, RTA the How and RTX the What.
- The RES triangle (Rhythm, Ethics, Semantics) became the RNS triad: Rhythm, Norms, Semantics. Ethics lives within norms.
- RTA² is retired; runtime assurance is now a pattern across the four RTA layers.
- Corpus and MetaCorpus sit in a six-level container hierarchy.
- New: the four RTA layers and the Runtime Control Loop; mandate as a first-class object with the Action Authorization Decision; the Human–Synthetic Enterprise and its seven deliverables; the human roles and the buddy agent; evidence and compliance as runtime properties; Bounded Constitutional Evolution.
The book
The full argument, in the book
The booklet is the compact edition. The book gives the full argument: RTSAX – The Architecture of the Human–Synthetic Enterprise, second edition, October 2026, more than 200 pages.
Every section of the booklet points to the chapter of the book where the argument is set out in full: the governable enterprise, the synthetic actor and its mandate, the runtime core, the container hierarchy, CoreSOS and IMUS, rhythm, the seven deliverables of the Human–Synthetic Enterprise, the domain configurations and the roadmap from pilot to operating model.
The book is available as a PDF to readers who register with their name, company and e-mail address. The download starts straight away, and the link is also sent by e-mail so it can be opened on another device.
The first edition, Real-Time Architecture, appeared in September 2025. The second edition was co-written and edited with Claude (Anthropic) and ChatGPT (OpenAI), under the author's direction.
Privacy notice
Who. This website is published by Otto Th.G. van Haaren, who is responsible for the data it collects.
What and why. When you register for the book, your name, company or organization, e-mail address and the time of registration are stored, together with a hashed form of your IP address that is used only to prevent abuse. These details are used to send you the download link for the book and to inform the author who has requested it. If you tick the box, your e-mail address is also used for occasional updates about RTSAX; every such e-mail contains a way to unsubscribe.
How long. Registrations are kept for as long as the book is offered through this site, and at most two years after your registration, unless you ask for earlier deletion. Download links expire after seven days.
Who else. Your details are not sold or passed on to third parties. The site is hosted in the Netherlands (TransIP). Fonts are loaded from Google Fonts, which means your browser requests them from Google's servers. The site sets no cookies and uses no analytics.
Your rights. You can ask to see, correct or delete the details held about you, and withdraw your consent for updates at any time, by e-mailing the address in the footer of this page.