02 / platform

Separation of powers

A coherent runtime for governed action.

Aetheria separates operator intent, machine cognition, institutional governance, execution authority, external effect, evidence, and recovery into distinct responsibilities.

System map

One proposal path. One claim-bearing boundary.

Every governed action follows the canonical path. Components enrich, inspect, deny, or execute the proposal without silently creating a second route around Gateway.

IdentityPurposePolicyDataRuntime state
  1. 01CognitionGenerates analysis and proposals
  2. 02GovernanceResolves delegated authority
  3. 03GatewayAdmits the exact registered effect
  4. 04Action railPerforms the bounded operation
  5. 05ReceiptBinds decision to observed state

StilleNacht independently evaluates the exact release and evidence boundary.

System responsibilities

Each layer carries one kind of authority.

01Atlas

Operator surface

Captures intent, presents the exact proposed effect, records the human decision, and exposes recovery state.
02Conversation & Aggregator

Cognition

Coordinates models, context, retrieval, and recommendations without acquiring execution authority.
03Governance

Authority resolution

Resolves actor, purpose, policy, data, scope, target, delegation, and runtime state.
04Gateway

Execution boundary

Admits only the exact authorized proposal to the exact registered action rail.
05Action rails

Bounded effects

Expose controlled operations with typed inputs, explicit targets, and constrained side effects.
06Receipts & recovery

Evidence continuity

Preserve decision, dispatch, observed outcome, denial, failure, unknown state, reconciliation, and recovery.
07Axiomatrix

Common contract spine

Carries shared envelope kinds and invariants across the installed system and governed domain packages.
08StilleNacht

Independent assurance

Evaluates the exact release and its evidence from outside the installed execution authority.

Governance inputs

Authority resolves from institutional facts.

Aetheria evaluates the request against the actor, delegated authority, purpose, policy, data provenance, target, scope, and live system state. An unresolved control blocks the rail.

Actor

Identity and delegation

Who is acting, whose authority they hold, and whether that delegation remains active.

Intent

Purpose and scope

Why the effect is requested, which target it reaches, and which limits bind it.

State

Policy and runtime truth

Which rules apply, what evidence is present, and whether conditions still permit execution.

Common spine

Domain depth without governance drift.

Domain packages add vocabulary, policy, evidence, and workflows. They do not replace the canonical execution path or transfer institutional judgment to the model.

01

Municipal Operations

Records, policy, minutes, workflow, and accountable adoption.

Deployment boundary
03

Healthcare

Governed advisory and operations with licensed human authority preserved.

Deployment boundary
04

Legal

Document, research, and workflow support under attorney and client authority.

Deployment boundary
No component authorizes itself.
Aetheria architecture invariant

Consequential action requires accountable authority.

Put a governed boundary between intent and effect.