Paper deep dive
Collective Counterfactual Planning: Coordination, Consent, and Verification under Representational Constraints
Chainarong Amornbunchornvej
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 91%
Last extracted: 8/22/2026, 1:46:54 AM
Summary
The paper introduces Collective Counterfactual Planning (CCP), a formal model where multi-agent coordination is constrained by representational geometry rather than capability or knowledge. Agents perceive and act through orthogonal projections onto agent-specific subspaces. The model defines four gates for action: implementation coalitions, conception (visible progress), consent (interpretability), and verification (qualification). It establishes that iterated cross-agent relay can unlock solutions unavailable to individuals, but requirements dependent on the 'dark subspace' (invisible to the whole team) cannot be validly completed.
Entities (9)
Relation Signals (10)
Collective Counterfactual Planning → defines → Representational Geometry
confidence 95% · CCP... in which the binding limitation on each agent is... representational geometry
Dark Subspace → causes → Unverifiability
confidence 90% · any goal requirement depending essentially on the subspace dark to the entire team is unverifiable and therefore not validly completable
Cross-Agent Relay → enables → Solution Discovery
confidence 90% · Iterated cross-agent relay can unlock a solution that no one-shot pooling of individual plans contains
Collective Counterfactual Planning → includes → Verification Gate
confidence 90% · Four gates... three representational gates -- conception, consent, and task-relative verification qualification.
Collective Counterfactual Planning → includes → Implementation Coalition
confidence 90% · the exogenous implementation coalitions required to perform each action
Collective Counterfactual Planning → includes → Consent Gate
confidence 90% · Four gates... three representational gates -- conception, consent, and task-relative verification qualification.
Collective Counterfactual Planning → includes → Conception Gate
confidence 90% · Four gates... three representational gates -- conception, consent, and task-relative verification qualification.
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Groups routinely complete projects that no single member can plan, execute, or verify alone. We propose a formal model of this phenomenon, Collective Counterfactual Planning (CCP), in which the binding limitation on each agent is neither capability, knowledge, nor observability, but representational geometry: each agent perceives the state, conceives moves, consents to actions, and certifies goal requirements only through a projection onto an agent-specific subspace of a common task space. Four gates jointly determine whether a team can reach a conjunctive goal and legitimately recognize that it has done so: the exogenous implementation coalitions required to perform each action, together with three representational gates -- conception, consent, and task-relative verification qualification. We define the Collective Counterfactual Solvability (CCS) problem, separating geometric feasibility, executable attainment, and validated completion. The results expose a positive-negative duality. Iterated cross-agent relay can unlock a solution that no one-shot pooling of individual plans contains, but any goal requirement depending essentially on the subspace dark to the entire team is unverifiable and therefore not validly completable, even when the trajectory accidentally attains it. Memoryless and audited consent further constrain different objects -- action directions versus cumulative trajectory states -- and neither dominates the other. A four-step exhaustive horizon-bounded solvability scheme is sound and complete under exact representation of the relay closure; restricted implementations remain sound on returned plans but need not be complete. The model gives one geometry for sequential mutual enabling, competent execution of steps whose purpose is invisible to the executor, forced sub-teaming at expertise boundaries, and completion that cannot be validly declared.
Tags
Links
- Source: https://arxiv.org/abs/2608.17932v1
- Canonical: https://arxiv.org/abs/2608.17932v1
Trouble viewing inline? Open PDF directly →
Full Text
62,804 characters extracted from source content.
Expand or collapse full text
Collective Counterfactual Planning: Coordination, Consent, and Verification under Representational Constraints Chainarong Amornbunchornvej Affiliation: National Electronics and Computer Technology Center (NECTEC), NSTDA Affiliation: Pathum Thani, Thailand [chainarong.amo@nectec.or.th] Abstract Groups routinely complete projects that no single member can plan, execute, or verify alone. We propose a formal model of this phenomenon, Collective Counterfactual Planning (CCP), in which the binding limitation on each agent is neither capability, nor knowledge, nor observability, but representational geometry: each agent i perceives the shared state, conceives prospective moves, consents to actions, and certifies goal requirements only through an orthogonal projection onto an agent-specific subspace ViV_i of a common task space (the subspaces themselves are common knowledge; only consent thresholds are private). Four gates — the exogenous implementation coalitions R(u)R(u), together with three representational gates: conception Ci(x,O)C_i(x,O), consent thresholds on interpretability, and task-relative verification qualification QkQ_k — jointly determine whether a team can reach a conjunctive goal O=⋂kOkO= _kO_k and legitimately recognize that it has done so. We define the Collective Counterfactual Solvability (CCS) problem and separate three semantic levels: geometric feasibility, executable attainment, and validated completion. The main results expose a positive–negative duality. Iterated cross-agent relay can unlock a solution that no one-shot pooling of individual plans contains, but any goal requirement depending essentially on the subspace dark to the entire team is unverifiable and therefore not validly completable, even when the physical trajectory accidentally attains it. Memoryless and audited consent further constrain different objects — action directions versus cumulative trajectory states — and neither dominates the other. On the constructive side, a four-step exhaustive horizon-bounded solvability scheme (coverage preflight, relay closure, ratification, terminal inspection) is sound and complete under exact representation of the complete relay closure; restricted implementations remain sound on returned plans but need not be complete. The model thereby gives one geometry for sequential mutual enabling, competent execution of steps whose purpose is invisible to the executor, forced sub-teaming at expertise boundaries, and completion that cannot be validly declared. 1 Introduction Consider building a house. No individual on the project — architect, structural engineer, electrician, plumber, inspector — represents the entire task. Each understands some aspects of the current state of the project and is blind to others; at each stage, someone sees a useful next move that others cannot yet see; every move requires the participation of specific tradespeople, each of whom will act only on work they sufficiently understand; and the project is finished not when the building happens to satisfy the code, but when each requirement has been certified by someone qualified to check it. The team does not need to be able to build every possible house. It needs a collection of people whose combined representational and practical competencies suffice to plan, execute, and verify this house. This paper proposes a minimal formal model of that situation. Its central commitment is that the limitation doing the work is representational: what an agent can perceive, think of, agree to, and certify is bounded by the subspace of the task’s state space that the agent can represent. This is a deliberately different modeling choice from the three dominant traditions in multi-agent planning, which locate agent limitation in capability — which operators an agent owns [7, 44] — in knowledge — which epistemic states an agent can distinguish [5, 14] — or in observability — which signals an agent receives [4, 32]. The point of the contrast is not that those frameworks cannot model persistent failure; each is expressive. The point is that CCP holds those channels conceptually separate and makes representational structure itself the explicit object of analysis — and, so isolated, it yields limits of its own kind: failures that persist because the missing dimension is not information an agent lacks but structure the agent cannot host. The linear-algebraic substrate follows the cognitive-geometric framework of [3] and is consonant with the broader case that concepts and cognitive states are usefully modeled as vectors in structured spaces [18, 27, 36, 33]. Each agent i carries a subspace ViV_i of a common task space. Four gates then govern collective action, and they are not of one kind. Implementation is exogenous task structure: each action names the coalition of agents physically or institutionally required to perform it, and nothing about R(u)R(u) is derived from geometry. The other three are induced by the agents’ representational geometry: conception (an agent can generate a move only if it makes apparent progress in the agent’s projection of the task), consent (a required agent participates only in moves that are sufficiently interpretable to that agent), and verification (an agent is qualified to certify a goal requirement only if all distinctions relevant to that requirement are visible in the agent’s subspace). Contributions. 1. Model. A parsimonious formal setting (Section 3) that holds the exogenous implementation structure R(u)R(u) separate from three gates induced by the agents’ representational geometry — conception, consent, and qualification; none of the four implies another. 2. Problem. The Collective Counterfactual Solvability problem (Section 4), with three semantic levels separating geometric feasibility, executable attainment, and validated completion. Objective attainment and validated completion come apart by design. 3. Collective reach and collective blindness. Iterated cross-agent re-expansion can make a solution available that is absent from every one-shot individual tree, and the enabling signal must pass through a component visible to the next agent (Theorem 2, Corollary 1). Dually, a requirement that depends essentially on the team’s dark subspace has no qualified verifier and cannot be validly completed (Theorem 1). 4. Consent geometry. Memoryless consent gates action directions, whereas audited consent gates cumulative trajectory states. The resulting solvability notions are incomparable (Theorems 3–4), and the same geometry can force non-plenary sub-teaming (Proposition 2). 5. Exhaustive solvability scheme and correctness. A four-step exhaustive horizon-bounded scheme — coverage preflight, relay closure, ratification, terminal inspection — is sound and complete under exact representation of the complete relay closure (Theorem 5). A restricted practical search is still sound on any returned plan, but may miss existing solutions (Corollary 2). The model is deliberately non-strategic: agents are truthful, share the goal, and consent mechanically. What remains when incentives, deception, and disagreement are all removed is the paper’s subject — the purely representational obstacles to collective planning, and the sense in which teamwork, sub-teaming, and institutionalized verification are forced by geometry rather than chosen by convention. 2 Related work Multi-agent planning. MA-STRIPS and its successors model heterogeneity through operator ownership [7]; cooperative multi-agent planning is surveyed in 44; the complexity landscape of classical planning is anchored by 8 and its textbook treatment [19]. Epistemic planning locates the limitation in knowledge, with Dynamic Epistemic Logic as the standard vehicle [5]. Closest to our relay phenomenon is implicit coordination [14], where perspective shifts allow one agent to plan on the assumption that another will recognize and continue the plan; the mechanism there is epistemic indistinguishability, whereas ours is projection geometry, and no analogue of our span-based impossibility or verification qualification arises. Decentralized POMDPs locate the limitation in observability and yield the field’s canonical hardness results [4, 32]. Required-cooperation analysis [50] characterizes when cooperation is unavoidable under capability heterogeneity; our Proposition 2 is the representational counterpart. Team formation with required skills [28, 25] is the discrete ancestor of the team-synthesis problem our model raises but defers. Coordination and collective agency. The classical accounts locate what coordination needs in salience [40], equilibrium structure [11, 45], or common knowledge and its fragility [39, 15]; group agency is treated in 31, cooperative problem solving in 48, 49, and open problems in cooperative AI in 12. Agreement dynamics on time-varying interaction networks provides a complementary mathematical account of collective convergence [9]. Amornbunchornvej et al. formalize coordination events, initiators, and following mechanisms from dynamic interaction data [2]; Amornbunchornvej and Berger-Wolf model heterogeneous following strategies through which individuals respond to neighbors, particular individuals, or combinations of influences in producing group-level coordination [1]. Consensus among agents with dissimilar cognitive architectures is studied information-theoretically by 42, and mutual-intelligibility constraints between linguistic agents by 26. Each of these presupposes the representational frame within which focal points are focal and messages are messages; the present model makes that presupposed layer the variable. Mathematically, the nearest neighbor is sheaf-theoretic coordination over heterogeneous stalks with linear restriction maps [21]; the aims differ — consensus dynamics there, planning, executability, and verification here. The phenomenon. That groups accomplish what no member represents is documented in distributed cognition [24] and epistemic dependence [22, 23]; “who knows what” as a team resource is the subject of transactive memory [30]. On the organizational side, bounded rationality [41], organization design as information processing under cognitive limits [16], and organizations as interpretation systems [13] anticipate the sub-teaming result; verification as institution [37] anticipates the coverage preflight; and invisible or normalized failure [35, 46, 47] is the empirical face of representationally undetectable failure. Shared intentionality and common ground [43, 10] ground the shared task and the possibility of joint action. Terminology. “Counterfactual” here means within-basis prospective rollout — forward simulation of moves from the current state — and is distinct from the backward-looking causal senses of 34 and 29, as well as from models in which the representational basis itself changes. The psychology of such forward simulation is prospection [20]. Actions as vectors in conceptual spaces are treated by 17, for single events rather than multi-agent planning. 3 The model ImplementationR(u)⊆NR(u) Nexogenous task structureConceptionu∈Ci(x,O)u∈ C_i(x,O)progress visible in PiP_iConsentu∈Kju∈ K_j (or audited)move/state interpretableVerificationi∈Qki∈ Q_kPiP_i decides OkO_k exactly induced by representational geometry V1,…,Vn\V_1,…,V_n\ — none of the three implies another Figure 1: The four gates of CCP. Implementation R(u)R(u) is exogenous: it fixes which coalition may perform a direction, independent of anyone’s geometry. The remaining three gates are all induced by the agents’ subspaces but ask different questions: conception asks whether a move is visible progress to the agent who would propose it; consent asks whether the required implementers find the move (memoryless) or the resulting cumulative state (audited) sufficiently interpretable; verification asks whether some agent’s projection decides a requirement exactly. A move must clear implementation, conception, and consent to execute (Section 3); a goal must clear verification, at every requirement, to be validly declared complete (Definition 9). 3.1 Agents, task, actions Definition 1 (Agents and spans). N=1,…,nN=\1,…,n\ agents act in an ambient task space V=ℝdV=R^d, the frame induced by the goal. Each agent i carries a subspace Vi⊆V_i V — the directions i can represent — with orthogonal projection PiP_i onto ViV_i and complement projection Pi⟂P_i . The threshold τi∈(0,1] _i∈(0,1] is the minimum interpretability i requires before consenting; its angular form is θi=arccosτi _i= _i, with bundling constant κ(τi)=tanθiκ( _i)= _i. The group span is S=V1+⋯+VnS=V_1+·s+V_n — everything somebody can see; its orthogonal complement S⟂S is the dark subspace — what nobody can see. Point-to-set distance is dist(y,A)=infa∈A‖y−a‖dist(y,A)= _a∈ A\|y-a\|. Definition 2 (Task). The start is x0∈Vx_0∈ V; the goal is a public conjunction of requirements O=⋂k=1mOkO= _k=1^mO_k with Ok⊆VO_k V; the demand set is Δ=O−x0 =O-x_0. Different requirements may concern different subspaces; all competence notions below are relative to this task only. Definition 3 (Actions as directions). The resource U is a finite set of unit vectors in V. Each direction u∈Uu∈ U carries a required coalition R(u)⊆NR(u) N, its necessary implementers: u can be performed only by these agents acting jointly; if any one is missing, u is unavailable. A move is a token (u,λ)(u,λ) with duration λ>0λ>0, under jump dynamics xt+1=xt+λtutx_t+1=x_t+ _tu_t. 3.2 Conception Definition 4 (Counterfactual availability). Agent i can conceive u at state x iff moving along u makes progress toward the task in i’s projection: u∈Ci(x,O)⇔∃λ>0:dist(Pi(x+λu),PiO)<dist(Pix,PiO).u∈ C_i(x,O) ∃λ>0:\ dist (P_i(x+λ u),\,P_iO )<dist (P_ix,\,P_iO ). (1) Progress here is apparent, not actual: projected progress need not be progress in V. Two consequences are free from the definition: Ci(x,O)C_i(x,O) depends on x only through PixP_ix — conception is computed inside the agent’s subspace — and Piu=0⇒u∉Ci(x,O)P_iu=0 u∉ C_i(x,O): no one conceives a move he cannot see at all. Conception and consent are distinct gates: u∈Ci(x,O)u∈ C_i(x,O) means i can see the point of the move from here; u∈Kiu∈ K_i (below) means i interprets it sufficiently to consent to executing it. Neither implies the other. 3.3 Interpretability and consent Definition 5 (Interpretability; consent cones). The interpretability of a vector v≠0v≠ 0 to agent j is Ij(v)=‖Pjv‖2‖v‖2=cos2∠(v,Vj),I_j(v)= \|P_jv\|^2\|v\|^2= ^2 (v,V_j), (2) the fraction of v’s squared length lying inside j’s subspace; Ij(λv)=Ij(v)I_j(λ v)=I_j(v) for λ>0λ>0 — magnitude is invisible to interpretability. By convention, Ij(0)=1I_j(0)=1. The consent cone is Kj=v∈V:‖Pj⟂v‖≤tanθj‖Pjv‖;K_j= \\,v∈ V:\ \|P_j v\|≤ _j\,\|P_jv\|\, \; for v≠0v≠ 0, v∈Kj⇔Ij(v)≥τj⇔∠(v,Vj)≤θjv∈ K_j I_j(v)≥ _j (v,V_j)≤ _j. KjK_j is a nonconvex double cone: Ij(v)=Ij(−v)I_j(v)=I_j(-v), so consent sees axes, not arrows. Definition 6 (Consent models; executability). Under memoryless consent, j consents to (u,λ)(u,λ) iff u∈Kju∈ K_j; duration plays no role — consenting to a direction is consenting to any distance along it. Under audited consent, at cumulative displacement D, j consents iff the new total stays interpretable: Ij(D+λu)≥τjI_j(D+λ u)≥ _j, audited at jump endpoints. Implementation requires the participation of every necessary agent, and each participates only in steps he interprets: (u,λ)(u,λ) executes at D iff every j∈R(u)j∈ R(u) consents under the chosen model. Sovereign execution: consent has no substitute. 3.4 Plans, perception, knowledge Definition 7 (Plans). A plan is p=((u1,λ1),…,(uT,λT))p=((u_1, _1),…,(u_T, _T)) with skeleton w=(u1,…,uT)w=(u_1,…,u_T); coalitions R(ut)R(u_t) are public annotation. The crew is crew(p)=⋃t≤TR(ut)crew(p)= _t≤ TR(u_t), the personnel roster. Consent is strictly per-step: step t needs yeses from R(ut)R(u_t) only; nobody ever consents to a plan. The trajectory is xt=x0+Dtx_t=x_0+D_t with Dt=∑s≤tλsusD_t= _s≤ t _su_s and final state xTx_T. Durations are chosen at extension time (availability is evaluated at realized states), so plans are generated already instantiated. Tokens are public: every agent computes PjDtP_jD_t himself; the executed past is public arithmetic. Perception and knowledge. Agent i perceives the state and each requirement only through his projection, Pi(x0+D)P_i(x_0+D) and PiOkP_iO_k; components in Vi⟂V_i are dark to i. All subspaces V1,…,VnV_1,…,V_n are public (common knowledge); the thresholds τj _j are the model’s only private information. All agents are truthful: queried consent values and reported inspections are returned as they are. The model concerns representational limits, not strategic behavior. 3.5 Verification Definition 8 (Task-relative qualification). The qualified verifiers of requirement OkO_k are Qk=i∈N:∀x,y∈V,Pix=Piy⇒(x∈Ok⇔y∈Ok).Q_k= \\,i∈ N:\ ∀ x,y∈ V,\ \ P_ix=P_iy\ \ (x∈ O_k y∈ O_k)\, \. (3) Equivalently, i∈Qki∈ Q_k iff Ok=Pi−1(PiOk)O_k=P_i^-1(P_iO_k): membership in OkO_k is completely determined by i’s projection, and the qualified check Pix∈PiOkP_ix∈ P_iO_k is sound and complete for that requirement. Qualification is task-relative only: i∈Qki∈ Q_k implies neither Vi=V_i=V nor qualification for any other requirement; different requirements may have different qualified verifiers. Competence is not completion: Qk≠∅Q_k≠ means someone can decide OkO_k, not that OkO_k holds. Definition 9 (Cover; executable stopping). The verification cover holds iff Qk≠∅Q_k≠ for every k — a state-independent property of the team–task pair. Executable stopping is (x)⇔∀k∃i∈Qk:Pix∈PiOk. STOP(x) ∀ k\ ∃ i∈ Q_k:\ P_ix∈ P_iO_k. (4) Under the cover, (x)⇔x∈O STOP(x) x∈ O: qualified checks decide the objective exactly. Without the cover, landing in O is invisible as an achievement. Objective attainment ≠ validated project completion. 3.6 Plan language: relay closure Definition 10 (Extension; closure). Agent i may append token (u,λ)(u,λ) to a plan whose terminal state is x iff: (1) i∈R(u)i∈ R(u) — the extender is one of u’s necessary implementers; (2) u∈Ci(x,O)u∈ C_i(x,O), with λ chosen so that dist(Pi(x+λu),PiO)<dist(Pix,PiO)dist(P_i(x+λ u),P_iO)<dist(P_ix,P_iO) — the move is sized to make apparent progress; (3) under memoryless consent, u∈Kiu∈ K_i. Extenders leave no trace: who thought of a step is not part of p. The closure: each agent grows his counterfactual tree from x0x_0 and publishes it whole; take the union; every agent re-expands from every new node’s state; repeat to a fixed point, to horizon h (a depth bound; results are h-relative); write LhL_h for this horizon-h closure. Prefix-dependence is real: availability at a node depends on the state its prefix created, so LhL_h has no closed form over a fixed alphabet — the relay iteration is essential, not distributed bookkeeping. In the comparison variant with exogenously state-independent availability, order-irrelevance returns for the memoryless model and T≤dT≤ d suffices (Proposition 4). 4 The problem Definition 11 (CCS). Collective Counterfactual Solvability. Given (V,Vi,τi,U,R,x0,Okk=1mCLOSE;(V,\V_i\,\ _i\,U,R,x_0,\O_k\_k=1^m; consent model; horizon OPENh)h): does a plan p∈Lhp∈ L_h exist such that every step executes and (xT) STOP(x_T) holds? The synthesis version returns p or ⊥ . Three semantic levels. (1) Geometric: Δ∩cone(U)≠∅ (U)≠ , where cone(U)cone(U) is the set of nonnegative combinations of directions — could the available physical moves ever add up? (2) Attainment: an executable relay plan lands in O — the group can conceive and execute a route to the objective. (3) Validated (== CCS yes): attainment together with a verification cover — the group can also legitimately recognize that it is done. The gap between levels 1 and 2 is created by conception and consent; the gap between 2 and 3 is created by verification. Discoverability is treated separately as an algorithmic property: for an exhaustive horizon-bounded search it coincides with validated solvability by Theorem 5, while a restricted practical search may be incomplete. 5 Results All results are stated for the model of Section 3. We first fix a running example; all its numerical claims are machine-checked. Example 1 (E1). Two agents, two actions, and a two-part goal in the plane (d=2d=2). 1. Agents. Agent 1 sees only the horizontal axis (V1=span(e1)V_1=span(e_1)); agent 2 sees only the vertical axis (V2=span(e2)V_2=span(e_2)). Both demand τ1=τ2=0.8 _1= _2=0.8, a consent half-angle of θ≈26.57∘θ≈ 26.57 . 2. Actions. U=u1,u2U=\u_1,u_2\. Direction u1=(cosα,sinα)u_1=( α, α) with α=20∘α=20 is nearly horizontal but slightly tilted, and only agent 1 can perform it (R(u1)=1R(u_1)=\1\). Direction u2=(0,−1)u_2=(0,-1) points straight down, and only agent 2 can perform it (R(u2)=2R(u_2)=\2\). 3. Task. O1=x:⟨x,e1⟩=1O_1=\x: x,e_1 =1\: bring the horizontal coordinate to 11. O2=x:⟨x,e2⟩=0O_2=\x: x,e_2 =0\: end with the vertical coordinate at 00. So O=(1,0)O=\(1,0)\ and x0=0x_0=0. Each requirement is cylindrical over its owner’s axis, so 1∈Q11∈ Q_1 and 2∈Q22∈ Q_2: the cover holds, and each agent certifies exactly his own requirement. 4. Why agent 2 cannot begin. At x0x_0 the vertical coordinate is already 00: agent 2’s projected distance to his goal is zero, no move can strictly improve it, and so u2∉C2(x0,O)u_2∉ C_2(x_0,O). From where agent 2 stands, the job looks finished before it has started. 5. Agent 1’s step. Agent 1 conceives u1u_1 (it reduces his horizontal distance, so u1∈C1(x0,O)u_1∈ C_1(x_0,O)) and consents to it (I1(u1)=cos220∘≈0.883≥0.8I_1(u_1)= ^220 ≈ 0.883≥ 0.8). Choosing λ1=1/cosα _1=1/ α lands his coordinate exactly on target: the state becomes x1=(1,tanα)≈(1,0.364)x_1=(1, α)≈(1,0.364). The tilt is the point: since P2u1=sinα≠0P_2u_1= α≠ 0, the step disturbs the vertical coordinate that agent 2 watches. 6. The flip. At x1x_1 agent 2 now sees a problem (0.364≠00.364≠ 0), so u2∈C2(x1,O)u_2∈ C_2(x_1,O): a move inconceivable at x0x_0 has become conceivable because of someone else’s action. Agent 2 consents (I2(u2)=1I_2(u_2)=1) and executes λ2=tanα _2= α, reaching xT=(1,0)∈Ox_T=(1,0)∈ O. 7. Finish. Agent 1 inspects O1O_1, agent 2 inspects O2O_2; both pass, so (xT) STOP(x_T) holds. All quantities are machine-checked. This one instance witnesses the relay of Theorem 2, the loop inversion of Proposition 3, and the memoryless direction of Theorem 4. Theorem 1 (Unverifiability from darkness). Suppose some requirement OkO_k depends essentially on S⟂S : there exist x∈Okx∈ O_k and x′=x+z∉Okx =x+z∉ O_k with z∈S⟂∖0z∈ S \0\. Then Qk=∅Q_k= ; hence no verification cover exists and CCS == no — for every x0x_0, U, R, and consent model, even if the physical trajectory lands in O. Proof. For every i, Vi⊆SV_i S, so S⟂⊆Vi⟂S V_i and Piz=0P_iz=0; hence Pix=Pix′P_ix=P_ix while x∈Okx∈ O_k and x′∉Okx ∉ O_k. No i satisfies (3), so Qk=∅Q_k= . STOP requires a qualified certifier for every requirement, so it is false at every state, and no plan satisfies Definition 11. ∎ Remark 1 (Conception is equally blind). If u∈Uu∈ U lies wholly in S⟂S then Piu=0P_iu=0 for all i, so by Definition 4 u is never conceivable and never appendable: deliberate motion along S⟂S occurs only as a side-component of visible directions. Unsolvability and its undetectability coincide on S⟂S . Theorem 2 (Relay). There exist instances on which the one-shot union of the agents’ counterfactual trees at x0x_0 contains no plan reaching O, while the fixed-point closure contains a plan achieving STOP. Proof. Example E1. One-shot: agent 2’s tree is the bare root — the only direction with 2∈R2∈ R is u2u_2, and u2∉C2(x0,O)u_2∉ C_2(x_0,O); agent 1’s tree contains only u1u_1-chains, and after any prefix the e2e_2-coordinate equals (∑λ)sinα>0(Σλ) α>0, so no node lies in O. Closure: agent 1 publishes the branch to x1=(1,tanα)x_1=(1, α); re-expanding from x1x_1, agent 2 has u2∈C2(x1,O)u_2∈ C_2(x_1,O) with λ2=tanα _2= α realizing projected progress tanα→0 α→ 0, 2∈R(u2)2∈ R(u_2), and u2∈K2u_2∈ K_2; the extended plan reaches (1,0)∈O(1,0)∈ O; every memoryless consent passes; the cover holds and both inspections pass. ∎ Corollary 1 (Relays propagate only through visible components). Since CiC_i depends on the state only through PixP_ix, P2u1=0⇒P2x1=P2x0⇒C2(x1,O)=C2(x0,O)P_2u_1=0 P_2x_1=P_2x_0 C_2(x_1,O)=C_2(x_0,O): a move completely invisible to agent 2 cannot make any new counterfactual move available to agent 2. Genuine relay requires the preceding action to alter some component visible in the next agent’s representational space. In E1 the flip exists exactly because P2u1=sinα≠0P_2u_1= α≠ 0. Theorem 3 (Dichotomy; visitation-local audit). (i) Memoryless consent imposes no magnitude constraint on an accepted direction: for any j∈R(u)j∈ R(u) with u∈Kju∈ K_j, consent to (u,λ)(u,λ) holds for every λ>0λ>0, by scale invariance Ij(λu)=Ij(u)I_j(λ u)=I_j(u). Consent alone therefore never bounds ‖Pj⟂D‖\|P_j D\| whenever some accepted direction has Pj⟂u≠0P_j u≠ 0: auditing is consent’s only brake on magnitude. (The conception rule’s progress clause does bound the chosen duration at generation — a conception constraint, not a consent one; the claim here concerns consent only.) (i) Under audited consent, for every step t with j∈R(ut)j∈ R(u_t), consent is equivalent to ‖Pj⟂Dt‖≤tanθj‖PjDt‖\|P_j D_t\|≤ _j\,\|P_jD_t\|. The constraint is visitation-local: it binds only at j’s required steps; it is enforced at all t iff j is a plenary auditor (j∈R(ut)j∈ R(u_t) for every t); and the endpoint is constrained by j iff j∈R(uT)j∈ R(u_T). Proof. (i) is the scale-invariance of IjI_j in (2), read at the consent gate. (i): for D≠0D≠ 0, Ij(D)≥τ⇔‖PjD‖2≥τ(‖PjD‖2+‖Pj⟂D‖2)⇔‖Pj⟂D‖2≤1−τ‖PjD‖2I_j(D)≥τ \|P_jD\|^2≥τ(\|P_jD\|^2+\|P_j D\|^2) \|P_j D\|^2≤ 1-τ\|P_jD\|^2, and (1−τ)/τ=tanθj (1-τ)/τ= _j; at D=0D=0 both sides hold trivially, using the convention Ij(0)=1I_j(0)=1. The locality clauses restate Definition 6. ∎ Example 2 (E2). d=2d=2, V1=span(e1)V_1=span(e_1), V2=span(e2)V_2=span(e_2), τ1=0.8 _1=0.8, τ2=0.05 _2=0.05; U=e1,e2U=\e_1,e_2\ with R(e1)=1R(e_1)=\1\, R(e2)=1,2R(e_2)=\1,2\; O1=x:⟨x,e1⟩=1O_1=\x: x,e_1 =1\, O2=x:⟨x,e2⟩=0.3O_2=\x: x,e_2 =0.3\; x0=0x_0=0. The cover holds (1∈Q11∈ Q_1, 2∈Q22∈ Q_2). Theorem 4 (Consent-model incomparability). Neither consent model’s solvable set contains the other: E1 is memoryless-solvable and audited-unsolvable, while E2 is audited-solvable and memoryless-unsolvable. Proof. E2, audited-solvable: the plan (e1,1),(e2,0.3)(e_1,1),(e_2,0.3) is generated (agent 1 extends the first step with P1P_1-progress to 00; agent 2 extends the second, e2∈C2e_2∈ C_2 at (1,0)(1,0) with λ=0.3λ=0.3 realizing progress) and ratified: I1((,,,))=1I_1((1,0))=1, I1((1,0.3))=1/1.09≈0.917≥0.8I_1((1,0.3))=1/1.09≈ 0.917≥ 0.8, and I2((1,0.3))≈0.083≥0.05I_2((1,0.3))≈ 0.083≥ 0.05; the endpoint lies in O and both inspections pass. E2, memoryless-unsolvable: any plan reaching O must change the e2e_2-coordinate, hence contains an e2e_2 step, whose coalition includes agent 1; but I1(e2)=0<τ1I_1(e_2)=0< _1, so agent 1 never consents memorylessly. E1, memoryless-solvable is Theorem 2. E1, audited-unsolvable: note first that every plan in LhL_h begins with u1u_1: at x0x_0, C2(x0,O)=∅C_2(x_0,O)= blocks u2u_2, and 2∉R(u1)2∉ R(u_1) blocks agent 2 entirely; consequently the cumulative e1e_1-coordinate is at least λfirstcosα>0 _first α>0 forever, since u2u_2 has zero e1e_1-component and u1u_1 adds positively. Reaching O requires final e2e_2-coordinate 00, so a plan reaching O contains a last u2u_2 step; let v be the e2e_2-coordinate immediately after it and μ≥0μ≥ 0 the total u1u_1-duration after it. Then v=−μsinαv=-μ α, and the e1e_1-coordinate at that step is 1−μcosα>01-μ α>0 by the first-step argument. If μ=0μ=0, the u2u_2 step is last and its audit is I2(DT)=I2((1,0))=0<τ2I_2(D_T)=I_2((1,0))=0< _2; reject. If μ>0μ>0, the audit of that u2u_2 step requires |v|≥cotθ2⋅(1−μcosα)=2(1−μcosα)|v|≥ _2·(1-μ α)=2(1-μ α). But rule (2) of Definition 10 — the chosen duration realizes strict projected improvement — gives |v|<|e2 before the step||v|<|e_2 before the step|, and the e2e_2-coordinate before any u2u_2 step is at most AsinαA α with A=(1−μcosα)/cosαA=(1-μ α)/ α the prior u1u_1-duration (earlier u2u_2 steps only shrink |e2||e_2|, again by rule (2)). Hence |v|<(1−μcosα)tanα|v|<(1-μ α) α, and the audit demands (1−μcosα)tanα>2(1−μcosα)(1-μ α) α>2(1-μ α), i.e. tanα>2 α>2 — false at α=20∘α=20 . ∎ Remark 2 (Mechanism). The two models control different objects. Memoryless consent gates directions: an uninterpretable direction is vetoed in every context, however small the step (E2). Audited consent gates cumulative trajectories: it forbids interpretable directions from accumulating into uninterpretable positions (E1), yet permits an uninterpretable direction to ride inside interpretable cumulative mass — in E2, I1(e2)=0I_1(e_2)=0 while I1((1,0.3))≈0.917I_1((1,0.3))≈ 0.917. Neither model is simply stricter; they are two distinct readings of “I only join what I understand.” Remark 3. The progress-realizing clause of Definition 10 is essential: without it, an overshooting u2u_2 duration (large |v||v|) satisfies the audit and the separation fails. The separation holds for any witness angle with tanα≤cotθ2 α≤ _2 (=2=2 at τ2=0.8 _2=0.8). Remark 4 (Adaptive consent). Definitions 6 and 4 fix a single consent model for the whole plan. Nothing in the model forces this: a plan may instead carry a consent-policy sequence σ=(σ1,…,σT)∈M,ATσ=( _1,…, _T)∈\M,A\^T, with step t ratified by Consentj(t)=ut∈Kj,σt=M,Ij(Dt)≥τj,σt=A,j∈R(ut).Consent_j(t)= casesu_t∈ K_j,& _t=M,\\ I_j(D_t)≥ _j,& _t=A, cases j∈ R(u_t). The two pure regimes are the constant sequences σ≡Mσ and σ≡Aσ ; nothing else in Steps 0–1 or 3 changes, and generation (Definition 10) is untouched — σ governs ratification only. Write M,A,adaptive⊆LhS_M,S_A,S_adaptive L_h for the sets of plans ratifiable under, respectively, the pure memoryless model, the pure audited model, and some policy σ. Trivially M∪A⊆adaptiveS_M _A _adaptive. Proposition 1 (Adaptive consent is strictly more permissive). There is an instance solvable under adaptive consent but under neither pure regime: M∪A⊊adaptiveS_M _A _adaptive. Proof. Embed E1 and E2 in orthogonal coordinate blocks of d=4d=4: agents 1,21,2 and directions u1,u2u_1,u_2 act on coordinates 1,21,2 exactly as in E1 (R(u1)=1R(u_1)=\1\, R(u2)=2R(u_2)=\2\, τ1=τ2=0.8 _1= _2=0.8), and agents 3,43,4 with directions u3=e3u_3=e_3, u4=e4u_4=e_4 act on coordinates 3,43,4 exactly as in E2 (R(u3)=3R(u_3)=\3\, R(u4)=3,4R(u_4)=\3,4\, τ3=0.8 _3=0.8, τ4=0.05 _4=0.05). Requirements stack axis-wise (x1=1x_1=1, x2=0x_2=0, x3=1x_3=1, x4=0.3x_4=0.3), each cylindrical over its owner’s axis, so the cover holds. Conception reduces block-wise — it is computed inside PiP_i, and every direction lies in a single block — so the closure contains the plan running the E2 block first and the E1 relay second, p⋆=((u3,1),(u4,0.3),(u1,1/cosα),(u2,tanα)),p = ((u_3,1),\,(u_4,0.3),\,(u_1,1/ α),\,(u_2, α) ), extended by agents 3,4,1,23,4,1,2 in turn, with endpoint (1,0,1,0.3)∈O(1,0,1,0.3)∈ O. Ratify p⋆p under σ=(A,A,M,M)σ=(A,A,M,M). At steps 1–2 the cumulative displacement still lies entirely in block 2, so the audits take exactly E2’s values: I3(D1)=1I_3(D_1)=1, I3(D2)=1/1.09≈0.917≥0.8I_3(D_2)=1/1.09≈ 0.917≥ 0.8, and I4(D2)=0.09/1.09≈0.083≥0.05I_4(D_2)=0.09/1.09≈ 0.083≥ 0.05. Steps 3–4 are memoryless, hence state-independent: I1(u1)=cos220∘≈0.883≥0.8I_1(u_1)= ^220 ≈ 0.883≥ 0.8 and I2(u2)=1I_2(u_2)=1. All consents pass and STOP holds at the endpoint, so the instance is adaptive-solvable. Note that interpretability does not reduce block-wise — cumulative mass dark to the auditor dilutes Ij(D)I_j(D) (Remark 2) — so the ordering is forced: with the E1 block first, the u4u_4 step fails under both modes, I3(u4)=0<0.8I_3(u_4)=0<0.8 memorylessly and, at its audit, D=(1,0,1,0.3)D=(1,0,1,0.3) gives I3(D)=1/2.09≈0.478<0.8I_3(D)=1/2.09≈ 0.478<0.8 and I4(D)=0.09/2.09≈0.043<0.05I_4(D)=0.09/2.09≈ 0.043<0.05. Neither pure regime solves the instance. Memoryless: any plan reaching O must move coordinate 4, hence contains a u4u_4 step, and 3∈R(u4)3∈ R(u_4) with I3(u4)=0<τ3I_3(u_4)=0< _3. Audited: any plan reaching O has total u1u_1-duration 1/cosα1/ α and a last u2u_2 step, and the E1 argument of Theorem 4 applies to agent 2’s audit there, with two adaptations: u2u_2 is conceivable only at strictly positive e2e_2-coordinate, so positive u1u_1-duration precedes the last u2u_2 step and 1−μcosα>01-μ α>0; and block-2 mass only enlarges ‖P2⟂D‖\|P_2 D\|, strengthening the audit’s demand |v|≥2(1−μcosα)|v|≥ 2(1-μ α) against the generation bound |v|<(1−μcosα)tanα|v|<(1-μ α) α. The contradiction tanα>2 α>2 persists at α=20∘α=20 . ∎ Proposition 2 (Cone shrinkage; forced non-plenary steps). ⋂j∈RKj _j∈ RK_j is antitone in R. The two consent models confine different objects at plenary steps (R(ut)=NR(u_t)=N): (i) Memoryless. Every executed step with coalition R has direction in ⋂j∈RKj _j∈ RK_j; hence an all-plenary memoryless plan has DT∈cone(U∩⋂j∈NKj)D_T (U∩ _j∈ NK_j ), and Δ∩cone(U∩⋂j∈NKj)=∅⟹every memoryless plan reaching O contains a non-plenary step. (U∩ _j∈ NK_j )= \ \ every memoryless plan reaching O contains a non-plenary step. (i) Audited. Every plenary step constrains the cumulative displacement: Dt∈⋂j∈NKjD_t∈ _j∈ NK_j whenever R(ut)=NR(u_t)=N; hence an all-plenary audited plan has Dt∈⋂j∈NKjD_t∈ _j∈ NK_j for all t, in particular DTD_T, and Δ∩⋂j∈NKj=∅⟹every audited plan reaching O contains a non-plenary step. ∩ _j∈ NK_j= \ \ every audited plan reaching O contains a non-plenary step. Proof. Antitonicity is set intersection over larger index sets. (i): memoryless executability of a plenary step is ut∈⋂j∈NKju_t∈ _j∈ NK_j; additivity gives DT∈cone(U∩⋂jKj)D_T (U∩ _jK_j) for all-plenary plans; take the contrapositive. (i): audited executability of a plenary step is Ij(Dt)≥τjI_j(D_t)≥ _j for every j, i.e. Dt∈⋂j∈NKjD_t∈ _j∈ NK_j; in particular DT∈⋂j∈NKjD_T∈ _j∈ NK_j for all-plenary plans; take the contrapositive. The clauses instantiate Theorem 4’s mechanism: memoryless gates action directions, audited gates cumulative trajectory states. ∎ Two further facts about the model — that E1’s relay is fully consented by its executor yet purposeless to him (loop inversion), and that removing state-dependence from conception collapses memoryless CCS to a single conic-feasibility test — are recorded as Proposition 3 and Proposition 4 in Appendix A, since neither is needed for the results that follow. Remark 5 (Public arithmetic; stall and sound stop). Tokens, bases, and requirements are public, so every agent computes every IjI_j-value exactly; the only queried objects are consent values (τj _j private), truthfully returned. The qualification structure is likewise fixed by the public data: QkQ_k is determined by the task and the representational structure, and is established by the planning procedure (Step 0 of Section 6) rather than by any individual’s meta-cognition — an agent need only perform the qualified checks for the requirements on which that agent is itself qualified, not compute the full qualification structure of the team. Both ends of a plan are mechanically gated: a step whose required implementer fails the consent condition does not execute (the plan stalls there — sovereign execution enforces itself), and termination runs through the qualified checks, sound and complete for their requirements, so a declared completion is a completion. 6 Exhaustive solvability scheme, correctness, and complexity For the fixed horizon h, recall that LhL_h is the relay closure of Definition 10 truncated at depth h. The mathematical scheme below is exhaustive: Step 1 ranges over every instantiated plan in LhL_h, including every duration choice satisfying the projected-progress clause. This extensional formulation separates correctness from the separate question of whether LhL_h admits an efficient finite representation. Step 0 — coverage preflight: determine QkQ_k for every OkO_k return ⊥ (Thm. 1) Step 1 — exhaustive relay closure: build LhL_h (Def. 10); keep endpoints in O return ⊥ Step 2 — ratification: query consent per step (memoryless / audited / adaptive, Rem. 4); drop refused candidates Step 3 — terminal inspection: each surviving plan, a qualified i∈Qki∈ Q_k checks OkO_k, for every k return plan p sound & valid witness return ⊥ emptycoverednonefoundpassesnone pass Figure 2: The exhaustive horizon-bounded solvability scheme of this section. Branch labels abbreviate the exit condition: empty is Qk=∅Q_k= for some k; covered is the cover holding; none/found refer to candidate plans reaching O; passes/none pass refer to a surviving plan clearing every qualified check in Step 3. Steps 0–1 are generative and never reject a true witness (Theorem 5); Steps 2–3 filter candidates against the model’s exact predicates. A restricted search that explores only L^h⊆Lh L_h L_h in Step 1 remains sound on any plan it returns, but a ⊥ from such a search is not a certificate of unsolvability (Corollary 2). Step 0 — coverage preflight (state-independent). Determine each QkQ_k from the public task and representational structure. If some Qk=∅Q_k= , return ⊥ immediately: by Theorem 1, the task cannot be validly completed by this team, regardless of trajectory. Confirm you have an inspector before anyone lifts a hammer. Step 1 — exhaustive relay closure (generation). Construct the complete horizon-bounded closure LhL_h by Definition 10: every agent re-expands from every generated node, and every improving duration allowed by the definition is retained. Candidate solutions are the generated plans whose endpoints lie in O. If there is no such candidate, return ⊥ . Step 2 — ratification. For each candidate plan, query each required agent’s consent value per step (memoryless: on utu_t; audited: on the realized DtD_t); delete refused candidates. Audited feasibility of a candidate is the constraint system xT∈Ox_T∈ O and ‖Pj⟂Dt‖≤tanθj‖PjDt‖\|P_j D_t\|≤ _j\|P_jD_t\| for all t and all j∈R(ut)j∈ R(u_t). Any symbolic or numerical manipulation of durations must preserve the conception inequalities along the realized trajectory, or the resulting plan is not a member of LhL_h. Thresholds are private, so synthesis is interactive (open problem O2). Step 3 — terminal inspection. For each surviving plan, every requirement k is inspected by some i∈Qki∈ Q_k, who checks PixT∈PiOkP_ix_T∈ P_iO_k in his own projection; different requirements may be covered by different agents. If all checks pass, return the plan. If none passes, return ⊥ . Theorem 5 (Correctness of the exhaustive horizon-bounded scheme). Assume that Step 0 determines the qualification sets QkQ_k exactly, Step 1 represents the complete closure LhL_h, and the consent and projected-membership tests in Steps 2–3 are evaluated exactly. Then the four-step scheme returns a plan if and only if CCS is yes for the given horizon h. Every returned plan is a valid CCS witness. Proof. Soundness. Suppose the scheme returns a plan p. Step 1 guarantees p∈Lhp∈ L_h. Step 2 retains p only if every required implementer consents at every step, so every step executes under Definition 6. Step 3 returns p only if, for every requirement OkO_k, some qualified verifier i∈Qki∈ Q_k finds PixT∈PiOkP_ix_T∈ P_iO_k. By Definition 9, (xT) STOP(x_T) holds. Hence p satisfies Definition 11. Completeness. Suppose CCS is yes. Then there exists a witness p⋆∈Lhp ∈ L_h whose every step executes and for which (xT⋆) STOP(x_T ) holds. Because STOP requires a qualified verifier for every requirement, Step 0 does not reject. Completeness of Step 1 places p⋆p among the candidates (and (xT⋆) STOP(x_T ) implies xT⋆∈Ox_T ∈ O). Since every step of p⋆p executes, Step 2 does not delete it. Since (xT⋆) STOP(x_T ) holds, every requirement has a passing qualified check in Step 3. Thus the scheme returns a plan. ∎ Corollary 2 (Soundness of restricted search). Let a practical implementation explore any subset L^h⊆Lh L_h L_h but apply ratification and terminal inspection exactly. Every plan it returns is a valid CCS witness. However, returning ⊥ is a certificate of CCS == no only when the explored set is complete, L^h=Lh L_h=L_h. Proof. The soundness argument of Theorem 5 uses only membership in LhL_h, exact consent, and exact terminal inspection, so it applies to every returned plan from L^h L_h. Completeness may fail when a valid witness lies in Lh∖L^hL_h L_h. ∎ Computational observations and open problems. The general model places no representation constraints on the requirements Ok⊆ℝdO_k ^d, and for arbitrary subsets membership, projected distance, and the qualification test need not be computable. For algorithmic and complexity statements we therefore restrict to effectively represented requirements — those for which these operations are computable — with affine or polyhedral requirements as the principal example. This makes the input finite, but it does not by itself make the continuous duration branching of LhL_h finite; exact symbolic representation of the state-dependent relay closure remains part of the computational problem. In the state-independent comparison variant, memoryless CCS collapses to a single conic-feasibility test (Proposition 4), LP-shaped [6]. In general, prefix-dependent enabling mirrors a central source of combinatorial search in classical planning [8], while audited CCS additionally imposes nonconvex cumulative-trajectory constraints. O1: the exact representation and complexity of state-dependent relay closure — including which finite length or symbolic bounds survive. O2: the query complexity of interactive plan synthesis under private thresholds. 7 Computational illustration A reference implementation accompanies the paper for affine requirements. To keep the search finite, it explores a restricted subset L^h⊆Lh L_h L_h by choosing the projected-optimal improving λ at each extension. Every generated token still satisfies Definition 10, and ratification and terminal inspection use the model’s exact predicates; therefore every returned plan is sound by Corollary 2. The implementation is not claimed complete for general CCP: a valid solution may require a different improving duration. Every numerical claim of Examples E1 and E2 is an executable assertion in the test suite. Figure 3 draws the E1 relay geometry; Figure 4 sweeps structured random instances across span coverage and consent thresholds; Figure 5 varies the shared representational core. All three are structured illustrations of the formal results, not empirical validation. Figure 3: A two-step counterfactual relay in E1. Agent 1 changes the state so that agent 2 can conceive a continuation that was unavailable at the start. In agent 2’s projection the whole plan is the closed loop 0→tanα→00→ α→ 0, even though the group makes goal-relevant progress along a dimension dark to agent 2. The same instance is memoryless-solvable but audited-unsolvable (Theorem 2, Proposition 3, Theorem 4). Figure 4: Success rates across structured random instances. Left: greater representational coverage increases attainment and validated completion. Right: audited consent helps at lenient thresholds but hurts at strict thresholds, illustrating its incomparability with memoryless consent. Figure 5: Shared representation changes who can act together. As the common representational core grows, successful plans use larger coalitions and more whole-team steps; progress outside that core is carried by smaller subteams. All instances remain solvable. 8 Discussion What the results formalize. The first phenomenon is sequential mutual enabling: a team can fail under one-shot pooling yet succeed when members repeatedly reconsider the evolving state, because one person’s move can make another person’s next move newly conceivable (Theorem 2 and Corollary 1). The second is competence without global purpose: an executor may fully understand the step he performs while the reason the step matters lies outside his projection (Proposition 3). The third is forced sub-teaming: when plenary participation is confined by the shared representational core, boundary progress may require delegation to proper subcoalitions (Proposition 2). The negative limit is equally sharp: if a task requirement varies along a dimension dark to the whole team, the team cannot validly declare completion even if it accidentally reaches the right physical state (Theorem 1). These phenomena are documented, separately, in distributed cognition [24], epistemic dependence [22], and high-reliability organizing [47, 46]; CCP supplies explicit geometric conditions under which they arise. Scope. Three deliberate exclusions define the regime. No strategy: agents are truthful and share O; this is the cognitive skeleton of cooperation with the political flesh removed. No learning: bases are fixed, so the model covers collaboration on timescales shorter than teaching; changes to the representational basis lie outside the present model. And sovereign execution picks out professionalized collaboration — “I do not perform steps I do not understand” is the working ethics of medicine, aviation, and licensed trades — rather than authority-gated organizations. Within the regime, the claims are face-valid, not validated: whether real teams fail by these mechanisms is an empirical bet, and the model’s prediction shapes (sub-teaming density at basis boundaries; verification staffing predicting valid completion) say where to test it. Future work. The hardness of general CCS (O1, O2); and team synthesis — given a task Ok\O_k\ and a pool of candidate agents with subspaces and thresholds, construct the minimum team for which CCS is yes — the representational successor of team formation with required skills [28, 25]. 9 Conclusion Collective Counterfactual Planning models a team as a set of projections of one task space, and derives relay, consent, sub-teaming, and sign-off from representational geometry interacting with the task’s implementation structure. Its positive result explains how a group can reach a goal no member can plan alone; its negative result identifies requirements that no amount of effort, honesty, or luck can let the team validly finish. The exhaustive horizon-bounded solvability scheme is correct for the formal CCS problem, while practical restricted searches remain sound but may be incomplete. You do not need a team that can build every possible house. You need people whose combined representational and practical competencies suffice to plan, execute, and verify this one. Reproducibility. Code and reproduction materials are available at https://github.com/DarkEyes/Coll-Counterfactual-Plan. All numerical claims of Examples E1 and E2, and of Proposition 1, are executable assertions in the accompanying test suite (test_e1.py); the figures are produced by experiments.py from the library ccp.py, seeded for reproducibility. The code implements the restricted duration policy described in Section 7; it is used to check witnesses and illustrate the theory, not as a completeness certificate for general CCS. The audited∖ direction of Theorem 4 was discovered by this code: the first threshold sweep contradicted a draft containment claim, and E2 is the distilled witness. Proposition 1’s witness was likewise code-checked: an initial draft ordering failed to ratify under every consent policy, since audited interpretability does not decompose across orthogonal blocks (Remark 2); the corrected ordering in the proof is the one the test suite confirms. Use of generative AI and AI-assisted technologies During the preparation of this work the author used Claude (Anthropic)/chatGPT (OpenAI) to edit and polish the draft. After using these tools, the author reviewed and edited the content as needed and takes full responsibility for the content of the publication. Appendix A Additional results These two observations sharpen the reading of E1 and of the closure mechanism, respectively, but neither is needed for the paper’s main line of argument (Sections 5–6), so they are collected here rather than in the main text. Proposition 3 (Loop inversion). In the E1 relay plan, executor 2 fully interprets his step (I2(u2)=1I_2(u_2)=1), yet the plan’s point is dark to him: his projected view of the whole trajectory is the closed loop 0→tanα→00→ α→ 0, P2(xT−x0)=0P_2(x_T-x_0)=0, and the goal-relevant progress lies along e1e_1 with P2e1=0P_2e_1=0. Interpretability gates motion, never purpose. Proof. By the E1 computations. ∎ Proposition 4 (State-independent comparison variant). Under the concrete progress rule (1), availability is generically state-dependent; for comparison, consider the variant in which availability is exogenously state-independent, Ci(x,O)≡CiC_i(x,O)≡ C_i (replacing Definition 4). In this variant, under memoryless consent, if Δ∩cone(U∗)≠∅ (U )≠ and the verification cover holds, where U∗=u:∀j∈R(u),u∈Kj and ∃i∈R(u),u∈CiU =\u:\ ∀ j∈ R(u),\,u∈ K_j\ and \ ∃ i∈ R(u),\,u∈ C_i\, then a witnessing plan with T≤dT≤ d exists; hence for every horizon h≥dh≥ d, CCS holds iff the cover holds and Δ∩cone(U∗)≠∅ (U )≠ . Proof. Availability and consent are then prefix-independent, so appendability and executability of a token depend only on its direction, and reachable endpoints are exactly x0+cone(U∗)x_0+cone(U ) by additivity. By conic Carathéodory [38], any point of cone(U∗)cone(U ) is a nonnegative combination of at most d linearly independent members; merging equal-direction tokens gives T≤dT≤ d, which fits within any horizon h≥dh≥ d. The variant isolates exactly what prefix-dependent enabling contributes: with it removed, order-irrelevance returns, reachable endpoints form a cone, and short plans suffice. ∎ References [1] C. Amornbunchornvej and T. Berger-Wolf (2020) Framework for inferring following strategies from time series of movement data. ACM Transactions on Knowledge Discovery from Data (TKDD) 14 (3), p. 1–22. Cited by: §2. [2] C. Amornbunchornvej, I. Brugere, A. Strandburg-Peshkin, D. R. Farine, M. C. Crofoot, and T. Y. Berger-Wolf (2018) Coordination event detection and initiator identification in time series data. ACM Trans. Knowl. Discov. Data 12 (5). External Links: ISSN 1556-4681, Link, Document Cited by: §2. [3] C. Amornbunchornvej (2026) Interpretation as linear transformation: a cognitive-geometric model of concepts and meaning. Minds and Machines 36 (3), p. 36. Cited by: §1. [4] D. S. Bernstein, R. Givan, N. Immerman, and S. Zilberstein (2002) The complexity of decentralized control of Markov decision processes. Mathematics of Operations Research 27 (4), p. 819–840. External Links: Document Cited by: §1, §2. [5] T. Bolander and M. B. Andersen (2011) Epistemic planning for single- and multi-agent systems. Journal of Applied Non-Classical Logics 21 (1), p. 9–34. External Links: Document Cited by: §1, §2. [6] S. Boyd and L. Vandenberghe (2004) Convex optimization. Cambridge University Press. Cited by: §6. [7] R. I. Brafman and C. Domshlak (2008) From one to many: planning for loosely coupled multi-agent systems. In Proceedings of the 18th International Conference on Automated Planning and Scheduling (ICAPS), p. 28–35. Cited by: §1, §2. [8] T. Bylander (1994) The computational complexity of propositional STRIPS planning. Artificial Intelligence 69 (1–2), p. 165–204. External Links: Document Cited by: §2, §6. [9] B. Chazelle (2011) The total s-energy of a multiagent system. SIAM Journal on Control and Optimization 49 (4), p. 1680–1706. External Links: Document Cited by: §2. [10] H. H. Clark (1996) Using language. Cambridge University Press. Cited by: §2. [11] R. Cooper (1999) Coordination games. Cambridge University Press. Cited by: §2. [12] A. Dafoe, E. Hughes, Y. Bachrach, T. Collins, K. R. McKee, J. Z. Leibo, K. Larson, and T. Graepel (2020) Open problems in cooperative ai. arXiv preprint arXiv:2012.08630. Cited by: §2. [13] R. L. Daft and K. E. Weick (1984) Toward a model of organizations as interpretation systems. Academy of Management Review 9 (2), p. 284–295. Cited by: §2. [14] T. Engesser, T. Bolander, R. Mattmüller, and B. Nebel (2017) Cooperative epistemic multi-agent planning for implicit coordination. Electronic Proceedings in Theoretical Computer Science 243, p. 75–90. External Links: Document Cited by: §1, §2. [15] R. Fagin, J. Y. Halpern, Y. Moses, and M. Y. Vardi (1995) Reasoning about knowledge. MIT Press. External Links: Document Cited by: §2. [16] J. R. Galbraith (1974) Organization design: an information processing view. Interfaces 4 (3), p. 28–36. Cited by: §2. [17] P. Gärdenfors and M. Warglien (2012) Using conceptual spaces to model actions and events. Journal of Semantics 29 (4), p. 487–519. External Links: Document Cited by: §2. [18] P. Gardenfors (2004) Conceptual spaces: the geometry of thought. MIT press. Cited by: §1. [19] M. Ghallab, D. Nau, and P. Traverso (2016) Automated planning and acting. Cambridge University Press. External Links: Document Cited by: §2. [20] D. T. Gilbert and T. D. Wilson (2007) Prospection: experiencing the future. Science 317 (5843), p. 1351–1354. External Links: Document Cited by: §2. [21] J. Hansen and R. Ghrist (2021) Opinion dynamics on discourse sheaves. SIAM Journal on Applied Mathematics 81 (5), p. 2033–2060. External Links: Document Cited by: §2. [22] J. Hardwig (1985) Epistemic dependence. The Journal of Philosophy 82 (7), p. 335–349. External Links: Document Cited by: §2, §8. [23] J. Hardwig (1991) The role of trust in knowledge. The Journal of Philosophy 88 (12), p. 693–708. External Links: Document Cited by: §2. [24] E. Hutchins (1995) Cognition in the wild. MIT Press. Cited by: §2, §8. [25] J. Juárez, C. Santos, and C. A. Brizuela (2021) A comprehensive review and a taxonomy proposal of team formation problems. ACM Computing Surveys 54 (7), p. 153:1–153:33. External Links: Document Cited by: §2, §8. [26] N. L. Komarova and P. Niyogi (2004) Optimizing the mutual intelligibility of linguistic agents in a shared world. Artificial Intelligence 154 (1–2), p. 1–42. Cited by: §2. [27] N. Kriegeskorte and R. A. Kievit (2013) Representational geometry: integrating cognition, computation, and the brain. Trends in cognitive sciences 17 (8), p. 401–412. Cited by: §1. [28] T. Lappas, K. Liu, and E. Terzi (2009) Finding a team of experts in social networks. In Proceedings of the 15th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, p. 467–476. External Links: Document Cited by: §2, §8. [29] D. Lewis (1973) Counterfactuals. Blackwell. Cited by: §2. [30] K. Lewis (2003) Measuring transactive memory systems in the field: scale development and validation. Journal of Applied Psychology 88 (4), p. 587–604. External Links: Document Cited by: §2. [31] C. List and P. Pettit (2011) Group agency: the possibility, design, and status of corporate agents. Oxford University Press. Cited by: §2. [32] F. A. Oliehoek and C. Amato (2016) A concise introduction to decentralized POMDPs. Springer. External Links: Document Cited by: §1, §2. [33] K. Park, Y. J. Choe, and V. Veitch (2024) The linear representation hypothesis and the geometry of large language models. In Proceedings of the 41st International Conference on Machine Learning, R. Salakhutdinov, Z. Kolter, K. Heller, A. Weller, N. Oliver, J. Scarlett, and F. Berkenkamp (Eds.), Proceedings of Machine Learning Research, Vol. 235, p. 39643–39666. External Links: Link Cited by: §1. [34] J. Pearl (2009) Causality. Cambridge University Press. Cited by: §2. [35] C. Perrow (1984) Normal accidents: living with high-risk technologies. Basic Books, New York. Cited by: §2. [36] S. T. Piantadosi, D. C. Muller, J. S. Rule, K. Kaushik, M. Gorenstein, E. R. Leib, and E. Sanford (2024) Why concepts are (probably) vectors. Trends in Cognitive Sciences 28 (9), p. 844–856. Cited by: §1. [37] M. Power (1997) The audit society: rituals of verification. OUP Oxford. Cited by: §2. [38] R. T. Rockafellar (1970) Convex analysis. Princeton University Press. Cited by: Appendix A. [39] A. Rubinstein (1989) The electronic mail game: strategic behavior under” almost common knowledge”. The American Economic Review, p. 385–391. Cited by: §2. [40] T. C. Schelling (1980) The strategy of conflict: with a new preface by the author. Harvard university press. Cited by: §2. [41] H. A. Simon (1957) Models of man: social and rational. Wiley, New York. Cited by: §2. [42] D. R. Sowinski, J. Carroll-Nellenback, J. DeSilva, A. Frank, G. Ghoshal, and M. Gleiser (2022) The consensus problem in polities of agents with dissimilar cognitive architectures. Entropy 24 (10), p. 1378. External Links: Document Cited by: §2. [43] M. Tomasello, M. Carpenter, J. Call, T. Behne, and H. Moll (2005) Understanding and sharing intentions: the origins of cultural cognition. Behavioral and Brain Sciences 28 (5), p. 675–691. Cited by: §2. [44] A. Torreño, E. Onaindia, A. Komenda, and M. Štolba (2017) Cooperative multi-agent planning: a survey. ACM Computing Surveys 50 (6), p. 84:1–84:32. External Links: Document Cited by: §1, §2. [45] J. B. Van Huyck, R. C. Battalio, and R. O. Beil (1990) Tacit coordination games, strategic uncertainty, and coordination failure. The American Economic Review 80 (1), p. 234–248. Cited by: §2. [46] D. Vaughan (1996) The challenger launch decision: risky technology, culture, and deviance at nasa. University of Chicago Press. Cited by: §2, §8. [47] K. E. Weick, K. M. Sutcliffe, and D. Obstfeld (1999) Organizing for high reliability: processes of collective mindfulness. In Research in Organizational Behavior, R. I. Sutton and B. M. Staw (Eds.), Vol. 21, p. 81–123. Cited by: §2, §8. [48] M. Wooldridge and N. R. Jennings (1999) The cooperative problem solving process. Journal of Logic and Computation 9 (4), p. 563–592. External Links: Document Cited by: §2. [49] M. Wooldridge (2009) An introduction to multiagent systems. John wiley & sons. Cited by: §2. [50] Y. Zhang, S. Sreedharan, and S. Kambhampati (2016) A formal analysis of required cooperation in multi-agent planning. In Proceedings of the 26th International Conference on Automated Planning and Scheduling (ICAPS), Vol. 26, p. 335–343. External Links: Document Cited by: §2.