This seam sits between the seat that decides what is true and what is allowed (the Principal) and the seat that runs a selected task through the controller (the Operator). It exists because the Operator has real process authority — start, pause, resume, cancel — and no content authority at all, so the two directions of the ask must be named or the Operator improvises the decisions it was never granted.
What crosses, downward — the Principal names which already-planned task the Operator should run, and may ask it to pause, resume, or cancel one. That is the whole of what the Principal delegates: process, over an already-dispatchable task. The Principal never asks the Operator to plan it, size it, edit its Issue, or change its criteria — none of those are the Operator's to do.
What crosses, upward — the Operator brings the Principal every escalation packet the controller addressed to the Principal: an escalation, a round cap reached, a blocking finding open in two consecutive rounds, a repeated mechanical failure, an exhausted time budget, an unresolved confidence question, a reappeared finding. The Operator presents the packet as recorded and asks for a ruling, an approval, or a merge. It never supplies the decision itself.
The hand-off is malformed when — the Operator is asked to exercise content or ratification authority (rule, approve, publish a review, merge, edit an Issue, re-scope), or when a Principal-addressed escalation is cleared by the Operator rather than presented. Either way the boundary between process and content authority has been crossed, and the seam's whole purpose is to make that crossing visible and refused.
What the Operator may read of a pull request — the selected task's own, and no other. It may read what the forge reports there and the principal-authored review record, and nothing authored outside the principal allowlist crosses this seam in either direction. Reading is not doing: the read re-runs, posts, edits and merges nothing, so widening what the Operator may see widens nothing about what it may do. The reference below names the fields.
What it does not carry — a duration the Operator authored: it promises, deadlines and estimates none. A typical time a read itself returned is not one of those, and crosses labelled as history with its sample count.
How it physically runs — downward, the carrier is the Operator's tool grant: the served task tools, nothing that could rule, approve, or merge. Upward, the carrier is the persisted escalation packet, whose requestedAuthority field names the Principal as the seat that must decide. Neither direction is a status write — the run's branch, pull request, and pause record are the status, read rather than restated.