Why “let the coordinator decide” is not a solution
A coordinator is convenient while the system lives in one process on one machine. As soon as the participants are distributed, the coordinator acquires three properties that are expensive in production: it is a throughput bottleneck, a single point of failure and the only one everyone is obliged to trust.
The third property is usually underestimated. “Trust” here is not about malice: a software bug, stale state or a partial loss of connectivity is enough for the coordinator to start handing out decisions that contradict what the others see. And the system will accept them — because trust is built into the architecture.
What the Byzantine fault model means
The usual fault model assumes that a node either works correctly or does not work at all. The Byzantine model allows for worse: the node is running but behaves arbitrarily — it sends different versions to different participants, replays old messages, signs with someone else’s name, votes twice.
For a network of autonomous agents this is not paranoia but an honest statement of the problem. A participant may be on someone else’s machine, run a different version of the code, suffer from clock drift or be compromised. The protocol has to stay correct under these conditions, not under ideal ones.
How one consensus cycle works
- The round’s leader sends out a signed proposal: which change to the shared state it proposes to commit.
- Each replica checks the proposal on its own — the validity of the state transition, the sequence number, the signature — and replies with its own signed vote.
- The leader collects a quorum of unique votes and sends out a commit certificate.
- Each replica checks every signature in the certificate, writes it durably to its log, and only then applies the change.
The arithmetic of fault tolerance
For a committee of n participants, the tolerable number of arbitrarily behaving replicas and the quorum size are calculated as follows:
f = floor((n - 1) / 3)
quorum = 2f + 1In practice: a committee of four survives one failed or malicious participant, provided the other three can communicate. The formula also carries an unpleasant truth — tolerance is paid for in participants: to survive two, you need seven. Consensus is expensive, and that is an argument for applying it selectively.
What the protocol must reject
- a repeat vote from the same participant — otherwise a single active node can make up the quorum;
- votes from anyone who is not on the committee;
- altered commands — the signature must cover the content, not the fact of sending;
- a wrong sequence or round number — protection against applying stale decisions;
- signature substitution and the replay of a previously intercepted message.
All of this is checked before a message reaches the consensus logic: the transport verifies the sender, the recipient, the timestamp and the nonce. The separation of responsibilities is fundamental here — consensus code must not deal with network security, otherwise a bug in one place destroys both properties.
Leader change and catch-up synchronisation
The leader may disappear or fall silent. The participants then vote to change the round, and leadership passes on. This is not an emergency procedure but a routine part of the protocol: the system has to keep working without human intervention.
A replica that was unavailable catches up from certificates: it requests every committed decision after its last number and applies them, checking the signatures. It does not need to trust whoever sent the history — the certificates are self-sufficient.
Where an agent system needs this
Not everywhere. Consensus is justified where a decision is shared and irreversible:
- a change to shared state that all participants see;
- admitting a new participant to the trusted perimeter;
- operations on resources where double spending is unacceptable;
- structural operations — merging a group of participants into one and unfolding it back again.
Everything else is the participants’ local decisions and pairwise agreements, which do not need the consent of the whole group. Trying to push every action through a committee turns a living system into a slow one: the price of consensus is paid for every decision, while the benefit appears only where divergence is genuinely dangerous.