# 4.4 DSoR acts (/ai-worker-paradigm/the-architecture-in-one-picture/dsor-acts)

---
type: Document
title: "4.4 DSoR acts"
description: "The layer between a worker and the company's real systems, the six checks it makes before any action, and how much of it exists today."
status: stable
order: 104.4
ksor:
  owner: team:panaversity
  audience: [ public ]
  approval:
    by: process:panaversity
    at: 2026-10-05T13:02:46Z
chapter: "04"
part: I
expert_status: required
concepts: [ "4.4" ]
last_verified: 2026-10-04
sources:
  - id: dsor
    title: "DSoR, the Data System of Record (Panaversity, GitHub, verified 2026-10-04)"
    resource: https://github.com/panaversity/dsor
generated:
  at: 2026-10-05T13:02:46Z
  by: esl-rewrite/1.2.0+ksor.1
trust_tier: unverified
build_id: sha256:c93b28093c2f70c60faae2645a693d881b657ff94d00f7dd9f8c06427ff61c87
dirty: true
ksor_version: 0.0.60
---

**In everyday life.** A company does not hand a new AP clerk the bank password and say "pay whatever looks right." The clerk gets a desk with a login of their own and a list of what they may do. They also get a spending limit, a manager who approves large payments, and a logbook.

A **DSoR**, or Data System of Record, is that desk, governed, for an AI Worker. It is the layer between the worker and the company's real systems.

Its rule fits in two sentences: **DSoR never takes the worker's word for anything. It checks for itself.**[^dsor] Every request to act passes the same checks.

1. **Who is asking?** The worker has its own identity, not a borrowed employee login.
2. **Under whose authority?** The worker acts for a named principal, inside limits that person was allowed to delegate.
3. **Which rules apply?** Limits and controls are checked by the system, not by the model.
4. **Does a person have to approve?** If so, the action waits until that person approves from their own login.
5. **What is true right now?** DSoR reads current state itself. It does not trust the state the worker reports.
6. **Has this already happened?** A retried request must not pay an invoice twice.

Each action leaves **evidence**: who asked, under whose authority, which rules ran, who approved and what happened.

The reason is not that models are careless. An agent can be confidently wrong. It can be tricked by text it reads. And it retries things a person would not. Thursday showed the first two. Through a DSoR, "approved" is not a status the worker can type. It is an event recorded when Dave approves from his own login. The lookalike email is text the worker read, so the most it can do is flag it.

**DSoR in this book.** DSoR is an open specification, and Part IV teaches it in depth. Until then, you set the worker's limits with the controls that products already offer: read-only access, approval steps, and no write access. Chapter 7 turns that into the Authority Envelope.

[^dsor]: DSoR, the Data System of Record, Panaversity.
