XOPS

The Platform  /  Arbiter

When operational events collide,
Arbiter decides what happens next.

Multiple systems, policies, operators, schedules, and agents can request changes against the same employee, device, identity, vendor, or entitlement at the same time. Arbiter detects the collision, protects the current Position, establishes the valid order of operations, and keeps every active Outcome aligned with reality.

Collisions are inevitable. Conflicting execution is not.

Where Arbiter fits

The XOPS Platform is the System of Action. Cortex exposes operational truth. The Convergence Engine converges state, compiles the valid runbook, and executes it deterministically. Arbiter protects that process when events collide or the operating reality changes.

Arbiter does not replace the Convergence Engine.

It ensures the engine never continues against stale, conflicting, or superseded assumptions.

The problem

Enterprise operations are distributed systems problems
disguised as tickets.

Workflows fire events. Operators submit tickets. Schedules trigger. APIs push updates. Policies expire. Agents and copilots propose actions. Every event proposes a change to one or more domain Positions.

Some events are compatible. Some depend on one another. Some supersede earlier intent. Some collide with an Outcome already in motion.

Arbiter determines which changes may proceed, which must wait, which must be merged, and which require the active runbook to be revised, paused, or recovered.

When events collide

Tuesday, 3:14 PM ET.
Five sources. One person. Eleven minutes.

A senior staff engineer accepts a promotion that comes with a relocation from Boston to Munich. Five operational events fire on her identity inside an eleven-minute window. None of them know about the others.

3:14 PM

Workday

Role change committed: Senior Staff → Principal Engineer.

3:18 PM

Equus Mobility

International transfer initiated: Boston → Munich, effective in 60 days.

3:21 PM

SailPoint policy run

Cost-center change flags entitlement re-certification.

3:23 PM

MDM compliance scan

Auto-flags her current laptop as soon-to-be out-of-region.

3:25 PM

Manager request

$180K budget increase tied to her current org chart row.

Without coordination

Five events. Multiple transitions.
No shared operating context.

  • The role change commits before the transfer. Her access map shows a Boston engineer with elevated Munich permissions.
  • The compliance scan stages a wipe of her laptop mid-deployment of a P1 release.
  • The budget request lands in the old cost center’s queue. Approved before the move. Booked to the wrong department.
  • By Friday, ops has stitched it together by hand. Three teams. Six tickets. Two reversals.

With XOPS

Five sources. One identity. One transition.

  • Arbiter detects the collision. Five events are attempting to change the same Employee, Identity, Device, Workplace, and Financial Positions within eleven minutes.
  • Arbiter establishes precedence and dependencies. The international transfer establishes the future location and cost center. The promotion resolves against that future Position. Device and access changes depend on the transfer effective date.
  • Arbiter protects active execution. The laptop action is held because the employee is inside a deployment freeze. The budget request is rerouted because the original org relationship is being superseded.
  • The Convergence Engine recompiles or continues. Once the valid order and Position are established, it executes the affected Outcomes under the revised plan. No silent drift. No manual hand-stitching.

The result is deterministic: given the same transfer date, deployment freeze, policy, active Outcomes, and current Position, Arbiter produces the same precedence and hold decisions every time.

The collision wasn’t the agents. The collision was five legitimate event sources, all correct, all uncoordinated. That’s what Arbiter exists to resolve.

How Arbiter resolves it

One operational entity.
Every competing transition coordinated together.

Event, policy, operator, schedule, or agent

Affected entity and current Position identified

Active Outcomes and locks evaluated

Collision classified

Deterministic precedence, dependency, merge, pause, or supersession decision

Convergence Engine continues, recompiles, or recovers

Conflict resolution must be deterministic too

Given the same confirmed Position, active Outcomes, governing policy, locks, and competing events, Arbiter produces the same collision classification, precedence decision, and execution disposition.

Arbiter does not ask an AI model to improvise which transition should win. Its decisions are governed by explicit policy, dependency rules, effective dates, priority, and the current operational state. Every decision can be reconstructed, explained, and replayed.

Same context, same decision

The same operational context produces the same coordination result.

Fully attributable

Every classification, dependency, precedence rule, hold, merge, and supersession is logged with the Position and policy that produced it.

Deterministic handoff

Arbiter deterministically directs the Convergence Engine to continue, wait, recompile, or recover.

Entity-scoped locking

Protects an employee, identity, device, contract, or other operational entity while related transitions are evaluated.

Collision classification

Determines whether events are compatible, dependent, conflicting, redundant, or superseding.

Precedence and serialization

Establishes which transition proceeds first and which must wait.

In-flight reconciliation

Re-evaluates the current Position when reality changes during an active Outcome.

Supersession and recovery

Pauses, revises, or recovers active execution when a newer event invalidates the original assumptions.

Governed intervention

Operators can inspect, override, pause, or release decisions under policy.

Arbiter establishes an entity-scoped operational lock inside XOPS. The underlying systems continue to operate, but competing state-changing actions are prevented from executing through the XOPS System of Action until their order and compatibility are resolved. This is a lock on governed execution, not a lock placed directly on Workday, ServiceNow, Intune, or other source systems.

In-flight re-evaluation

Arbiter continuously evaluates whether the assumptions behind active Outcomes remain true as new events arrive.

The truth gate applies here too

When Arbiter cannot establish a valid order from confirmed state and governing policy, it does not guess. The affected Outcomes pause and surface as a governed exception.

Not every collision is the same

Compatible

Two actions affect different attributes and can proceed in parallel.

Dependent

One action requires another to complete first.

Conflicting

Two actions request incompatible states.

Redundant

A newer event requests a state already being achieved.

Superseding

A new event invalidates or replaces an Outcome already in progress.

Ambiguous

The available state is insufficient to determine the valid order, so execution pauses.

What happens to the compiled runbook

Arbiter deterministically resolves the collision and updates the governing context. The Convergence Engine then continues the existing runbook, holds execution, recompiles against the new Position, or enters compensating recovery as directed.

Continue

The existing runbook continues unchanged.

Wait

Execution is held until a dependency completes.

Recompile

The runbook is recompiled against the new Position.

Recover

The current runbook is compensated or recovered because the original Outcome is no longer valid.

Human governance

Pause governed execution from any source. Override Arbiter’s decision with reason and scope. Inspect the competing events, policy, Position, and active runbook. Every intervention is attributable and auditable.

Reality changes while work is in motion.
Arbiter keeps execution valid.

When events collide, dependencies shift, or a newer transition supersedes an active one, Arbiter protects the current Position and ensures the Convergence Engine proceeds only against valid assumptions.

One operational Position. Every competing transition governed. No uncontrolled execution.