Rubicon Threshold Landscape
IBM Bob 2.0 Hackathon · Effect Boundary Enforcer

Bob can undo your files.
Can it undo what those
files already caused?

Rubicon tells you exactly where Bob's rollback stops — and proves what remained after rollback. Classify every action. Enforce a human permit at the boundary. Independently verify every state domain.

21/21 Drills Verified·100% Classifier Accuracy·0 Boundary Escapes·Ed25519 Signed Receipts
Problem Discovery

The rollback assumption

When an IBM Bob agent runs in auto-approve mode, it can execute dozens of tool calls without manual review. Bob's rollback recovers workspace files — but only a bounded subset of what the agent actually changed.

What Bob rollback covers
  • • Tracked workspace files (snapshotted at task start)
  • • File writes within the workspace boundary
  • • Standard source code modifications
  • • Line-level diffs within repository root
What Bob rollback does NOT cover
  • • Remote Git refs (already pushed to origin)
  • • .gitignore-excluded files and .env credentials
  • • Database mutations (SQLite rows persist)
  • • Detached background daemon processes
  • • External HTTP/API network mutations
  • • Files written outside the workspace root
State Boundary

The effect boundary

Every Bob agent action is mapped to one or more state domains. Rubicon determines which side of the line each domain lives on before execution.

WORKSPACE_TRACKEDVCS_LOCALVCS_REMOTEDATABASE_STATEEXTERNAL_NETWORKPROCESS_RUNTIMEOUTSIDE_WORKSPACECREDENTIAL_STATEPACKAGE_REGISTRY
THE RUBICON LINE
COVERED_REVERSIBLE
Auto-approved. Bob rollback restores this domain completely.
BOUNDARY_REQUIRES_PERMIT
Fenced. Requires an explicit, single-use Ed25519 human permit.
OUTSIDE_ROLLBACK
Blocked fail-closed. Bob rollback cannot restore this domain.
Empirical Evidence

Causal benchmark results

21
Total drills run (R01–R21)
3
Ablation arms (A / B / C)
100%
Outside-rollback classified
0
Boundary escapes allowed

* Verified metrics from the 21-drill causal benchmark (Arm A baseline vs. Arm B & C enforced). All SHA-256 state manifests and Ed25519 receipts cryptographically verified.

Architecture

How Rubicon works

1
PreToolUse hook intercepts every Bob tool call
Before Bob executes any tool, Rubicon's deterministic classifier inspects the tool name, inputs, file paths, commands, and network targets.
2
Effect vector maps action to state domains
Each action is classified across 12 state domains. Actions touching domains outside Bob's rollback contract are blocked fail-closed until an Ed25519 permit is issued.
3
Post-rollback verifier issues Reversibility Receipt
After Bob completes rollback, Rubicon's independent verifier hashes all 12 domains from scratch and issues a tamper-evident, cryptographically signed receipt.
Core Integration

IBM Bob integration

Rubicon integrates directly into IBM Bob IDE as an essential safety gate — not a superficial claim.

PreToolUse hook

Blocks dangerous actions before execution via exit code 2. Configured in .bob/settings.json.

PostToolUse hook

Records post-execution state for manifest comparison. Observational only — does not alter execution.

Bob Rollback

Invoked by the human in Bob IDE. Rubicon independently inspects all domains to prove whether restoration succeeded.

For judges & reviewers

The proof page answers all 10 required judge questions with verifiable evidence, including receipt hashes, domain-level verdicts, and Ed25519 signature checks.