Independent verification
Execution success is not Task success. After Codex exits, Argos runs declared checks and rereads final Git and filesystem state separately from the agent's completion claim. Execution API keys cannot submit verification.
Frozen plan
The CLI builds this plan before controlled mutation begins and asks for all criteria files/directories: tests, fixtures, scripts, configuration and local helpers defining success. Declare literal existing paths, not globs. Argos does not infer the dependency closure. The declaration is part of the plan hash; baseline contents, modes and directory membership must remain stable before and after checks. Missing or changed criteria prevent VERIFIED. Redefining criteria requires a new human-reviewed Task.
{
"outcomeRequirement": "repository_change_required",
"changedPaths": ["src/auth/password-reset/handler.ts"],
"protectedPathsUnchanged": ["src/auth/session/token.ts"],
"dependencyFilesUnchanged": ["package.json", "package-lock.json"],
"criteriaPaths": ["package.json", "package-lock.json", "tsconfig.json", "tests", "scripts"],
"commands": [
{ "name": "typecheck", "executable": "npm", "args": ["run", "typecheck"] },
{ "name": "focused_tests", "executable": "npm", "args": ["test"] },
{ "name": "build", "executable": "npm", "args": ["run", "build"] }
]
}Verification outcomes
VERIFIED
Every required check passed and the declared repository outcome was observed.
FAILED
The verifier worked and conclusively observed a failed engineering condition.
UNCERTAIN
Environment, configuration, timeout, or unreadable state prevented a reliable conclusion.
The verifier exits 0 for VERIFIED, 1 for deterministic FAILED, and 2 for UNCERTAIN.
Required outcome integrity
If an operation was authorized and recorded as executed but the required final repository outcome is absent, execution remains EXECUTED while verification becomes FAILED.
Deterministic verification proves the declared engineering contract. It does not prove broad semantic business intent beyond that contract.