Before Agents Act: Assurance-Aware Semantic Scheduling for Evidence Acquisition in Distributed Systems
Abstract
Tool-using agents can initiate consequential infrastructure changes, yet evidence required for admission may expire while other checks run or depend on a shared fault domain. We formulate evidence acquisition as joint witness selection and scheduling under quorum, diversity, freshness, deadline, and resource constraints. Assurance-Aware Semantic Scheduling (AAS) combines integer-program selection, dispatch-aware temporal scheduling, bounded diagnostic expansion, and receipt-aware repair. Formal results state the assumptions needed for dispatch-time freshness and finite diagnostic expansion. In three generated infrastructure workloads, AAS produces 1,075/1,200 valid candidates versus 647/1,200 for constraint-aware forward scheduling; stale candidates fall from 440 to 12. Paired sensitivity studies reuse the same instances and operation latency draws across parameter settings. A corrected timeout intervention finds 18/20 admissions with repair or full resynthesis versus 0/20 for a static plan, with lower committed cost when receipts are reused. On 20 constructed cases requiring a certified decomposition cut, refinement recovers an oracle-matching feasible plan every time. These are controlled simulation results; the bounded oracle shares a temporal search component, and transfer to deployed systems remains untested.
Figures & tables
| Scheduler Policy | Valid Dispatch | Stale Failures | Correlated Failures | Safe Refusal | Admitted Latency (s) | Admitted Cost ($) | Replan (ms) |
|---|---|---|---|---|---|---|---|
| Serial Forward (ASAP) | 29.75% (357/1200) | 0.0% (0/1200) | 61.5% (738/1200) | 8.75% (105/1200) | 7.70 (p95: 7.70) | $0.11 | — |
| Greedy Cost Portfolio | 28.17% (338/1200) | 1.58% (19/1200) | 61.5% (738/1200) | 8.75% (105/1200) | 2.40 (p95: 2.40) | $0.11 | — |
| Static Parallel | 53.92% (647/1200) | 36.67% (440/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 4.18 (p95: 6.51) | $0.14 | — |
| AAS (Proposed) | 89.58% (1075/1200) | 1.0% (12/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 5.50 (p95: 12.40) | $0.15 | — |
| Constraint-Aware Forward | 53.92% (647/1200) | 36.67% (440/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 4.18 (p95: 6.51) | $0.14 | — |
| Separate Sched (No Refinement) | 89.58% (1075/1200) | 1.0% (12/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 5.50 (p95: 12.40) | $0.15 | — |
| Scheduler Policy | Valid Admitted | Stale Refused | Correlated Blocked | Explicit Safe Refusal | Admitted Latency (s) | Admitted Cost ($) |
|---|---|---|---|---|---|---|
| Serial Forward (ASAP) | 29.75% (357/1200) | 0.0% (0/1200) | 61.5% (738/1200) | 8.75% (105/1200) | 7.70 | $0.11 |
| Greedy Cost Portfolio | 28.17% (338/1200) | 1.58% (19/1200) | 61.5% (738/1200) | 8.75% (105/1200) | 2.40 | $0.11 |
| Static Parallel | 53.92% (647/1200) | 36.67% (440/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 4.18 | $0.14 |
| AAS (Proposed) | 89.83% (1078/1200) | 0.75% (9/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 5.50 | $0.15 |
| Constraint-Aware Forward | 53.92% (647/1200) | 36.67% (440/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 4.18 | $0.14 |
| Separate Sched (No Refinement) | 89.58% (1075/1200) | 1.0% (12/1200) | 0.0% (0/1200) | 9.42% (113/1200) | 5.50 | $0.15 |
| Ablation Variant | Valid (%) | Stale (%) | Corr (%) | Refusal (%) | Lat (s) | Cost ($) |
|---|---|---|---|---|---|---|
| A: no EFD selection | 33.33% (10/30) | 0.0% (0/30) | 66.67% (20/30) | 0.0% (0/30) | 2.40 | $0.11 |
| B: no JIT scheduling | 63.33% (19/30) | 36.67% (11/30) | 0.0% (0/30) | 0.0% (0/30) | 4.19 | $0.14 |
| C: no adaptive repair | 63.33% (19/30) | 36.67% (11/30) | 0.0% (0/30) | 0.0% (0/30) | 4.19 | $0.14 |
| D: no receipt reuse | 93.33% (28/30) | 6.67% (2/30) | 0.0% (0/30) | 0.0% (0/30) | 5.15 | $0.15 |
| E: no refinement | 93.33% (28/30) | 6.67% (2/30) | 0.0% (0/30) | 0.0% (0/30) | 5.15 | $0.15 |
| F: greedy forward | 33.33% (10/30) | 0.0% (0/30) | 66.67% (20/30) | 0.0% (0/30) | 7.70 | $0.11 |
Appendix figures & tables1 asset
Supplementary material from the paper’s appendix.
Appendix
| Operation Class | Example Implementation | Mean Cost | Nominal Latency | Lifespan | Consequential? ( ) | Primary Epistemic Fault Domains ( ) |
|---|---|---|---|---|---|---|
| Passive Telemetry | Prometheus scrape / eBPF | $0.0001 | 40 ms | 5 s | No | Local kernel, metrics daemon |
| Log Audit | Loki / OpenSearch query | $0.002 | 250 ms | 30 s | No | Log forwarder, search index |
| Hardware Attestation | TPM quote / AWS Nitro quote | $0.005 | 350 ms | 300 s | No | Hardware root-of-trust, CA |
| Static SMT Proof | Z3 / Dafny verification | $0.02 | 1.8 s | No | Solver binary, CPU architecture | |
| Redundant Model | Independent LLM judge | $0.03 | 1.2 s | 60 s | No | Model weights, inference stack |
| Consensus Query | Raft / Paxos quorum read | $0.001 | 80 ms | 10 s | No | Consensus network quorum |