Human
Defines architecture and policy, authorizes task class and provider use, judges evidence, approves editorial copy, and separately authorizes publication, deployment, and delivery.
BOUNDARY · never inferred from a tool permissionThe runtime topology behind a human-governed, agentic intelligence system.
Authority does not follow access. The Human retains consequential decisions. The Orchestration Agent coordinates work and verifies evidence. SIGNIT governs the intelligence pipeline. Bounded Agents execute only the capabilities named in an exact work order.
The system separates probabilistic reasoning from deterministic enforcement and human authority. Arrows show data and control flow, not automatic permission.
System map · scroll horizontally on smaller screens →
Source plane observation + provenance
Intelligence plane probabilistic analysis under deterministic gates
Orchestration plane operator-side coordination + verification
Deterministic control plane non-probabilistic enforcement
An agent is not just its model. The model is the reasoning engine inside a governed runtime envelope. The complete agent includes identity, scope, inputs, capabilities, working state, output contract, verification, and an authority gate.
Agent anatomy · left to right execution contract →
who acts, exact objective, accountable owner, task boundary
frozen inputs, source hashes, lineage, freshness, exclusions
allowed actions, prohibited actions, path and time limits
authorized model profile, deterministic tools, permissions
ephemeral workspace, checkpoint, manifest, session binding
typed artifact, citations, uncertainty, complete provenance
separate checks re-establish claims, sources, and constraints
Human decides whether output may influence action or publication
Agent output is evidence, not authority.
Every load-bearing claim must preserve the path from observation to source, verification, adversarial challenge, current-run finality, and downstream use.
Deterministic controls establish eligibility; the Orchestration Agent coordinates and verifies; the Human decides whether the system may cross a consequential boundary.
No claim advances without origin, retrieval context, transformations, and dependent-claim trace.
A stale pass, older recheck, or route signal cannot override a current conflict.
Exact-run and canonical evidence outrank derived state, mirrors, agent reports, and conversational memory.
Every agent operates inside an explicit tool, model, path, mutation, and output envelope.
Approval binds to one task or one byte-exact package. A changed byte invalidates publication authority.
Execution reports are not accepted as proof; load-bearing results are re-established from exact evidence.
FAIL CLOSED: if identity, authority, evidence freshness, active-writer state, exact package binding, or verification is ambiguous, stop. Bind the missing fact from its authoritative source before proceeding.