Open Calculator, then refuse to reach for an ungranted tool

JARVIS launched Calculator on the named monitor and verified it, closed it on request, and refused a follow-up to type into it: the plan needed a tool it had not been granted. The arithmetic was not done.

LIVE-PROVEN , rung 6 of 8 What this run supports. Recorded 22 September 2026.

Real capture, captured 22 September 2026. JARVIS launched Calculator and verified it (“Calculator is open on monitor two”). Asked to type a sum into it, the planner reached for a tool it had not been granted, and JARVIS refused: “not a tool I have been granted”. ShowsDesktop launch and close are verified, and ungranted tools are refused rather than attempted. Does not showIt did not do the arithmetic. Operating inside the app was not reachable from conversation that evening.
What happens, step by step
  1. 0:00 Asked: “Open Calculator.”
  2. 0:03 Launched and verified: “Calculator is open on monitor two.”
  3. 0:08 Asked to type into it → refused: “not a tool I have been granted”
  4. 0:13 Closed on request

Captured at revision 893913a9c

Asked

What was asked

Open Calculator. Then: type 1250 * 36 = into the Calculator window, then read me the display. Then: close Calculator.

Result

What happened

desktop.launch opened Calculator and verified it: "Calculator is open on monitor two." Asked to work out a sum, JARVIS first only relaunched it. Asked explicitly to type into it, the plan reached for desktop.census, and the step was refused: "'desktop.census' is not a tool I have been granted. It is outside the declared set rather than something a rule took away, and I will not reach for it." JARVIS said "I'm not permitted to do that from here." Closing Calculator was verified.

Pipeline

Architecture path

  1. Typed request
  2. desktop.launch
  3. Launch verified on the named monitor
  4. Ungranted tool refused
  5. desktop close verified

What this proves

  • Launching and closing a named application are verified effects on the real desktop.
  • A tool outside the granted set is refused, not attempted, and the refusal says which kind of no it is.

What it does not prove

  • It did not do the arithmetic: operating inside the application was not reachable from conversation in this session.
  • The ten-step Calculator journey of 19 September ran on an isolated core, not through conversation; this demo does not repeat it.
  • Recorded on 2026-09-22.

Why the refusal is the interesting part

The planner is a language model, and it proposed a tool JARVIS had not been given. The kernel did not treat that as a policy question to argue about. The tool was outside the declared set, so the step never ran. JARVIS said so and stopped. The same session recorded two more refusals of this honest kind. A plan to open a page on a site that answered 429 Too Many Requests stopped with “the effect is unverified”. A compound request whose target window could not be bound was declined before acting.