The solution
Long-lived AI agents may replace their models, orchestration harnesses, interaction surfaces, and hosts while needing to retain identity, memory, and executable body lineage. In current practice those are entangled with the runtime, so a swap means rebuilding the agent from scratch.
The design separates a continuity-bearing substrate P_t=(I_t, M_t, B_t) from replaceable execution and interaction bindings. Six continuity invariants and a quiesce-checkpoint-validate-bind-rehydrate-resume protocol govern state preservation, capability changes, and continuation authority; Enoch implements the design through a reusable software body, private installed state, provider contracts, and fenced migration.
The evidence is mechanical, and deliberately scoped: an operational case retained an established instance's identity, nonempty memory, body revision, and historical task IDs across a host change, a joint Codex-to-Claude model-and-harness swap, and a chat-surface substitution; a cross-host task resumed from a verified artifact checkpoint; and a supervised Codex-Muse-Codex study completed five ordinary round trips and five matched same-runtime controls on their first attempts.
A planned worker interruption recovered through the native task API with the checkpoint preserved, a stale reply rejected, and one task completion recorded. The authors state these results establish mechanical continuity for tested deployments and bounded workflows — not behavioral equivalence, arbitrary-task portability, or unattended reliability.
Why it worked
Continuity invariants make 'the same agent' checkable instead of asserted.
Binding-time validation catches capability changes before the agent resumes work.
Fenced migration limits what a new runtime can do to old state.
Checkpointed tasks let an interrupted agent resume without duplicating effects — a stale reply was rejected and exactly one completion recorded.
What can be applied
Treat 'which model runs the agent' as a replaceable part. If identity and memory live outside the runtime, swapping the model becomes routine maintenance instead of starting over.
Aftermath
Public artifacts live at github.com/our-ark/enoch-muse-runtime. Version 2 (September 2026) added Claude/host/surface migrations, checkpointed tasks, controls, and fault-recovery evidence; the authors explicitly scope the claims to bounded workflows.
FOLLOW THE EVIDENCE