the context layer.
a user-controlled contract for moving the minimum useful context across models, agents & applications.
one boundary. six recorded steps.
each exchange starts with a declared purpose & ends with a receipt. raw vault access never crosses the boundary.
01capturepreserve origin
record the source event, time, identity & payload digest before interpretation.
02normalizederive with provenance
derive structured claims while retaining source references, timestamps & confidence.
03vaultretain authority
keep encrypted originals & policy state inside user-controlled authority. raw data never enters bundles or receipts.
04decideallow, reduce, approve or deny
evaluate purpose, recipient, selectors, actions & expiry before granting any context.
05bundleminimum useful context
issue recipient-bound, expiring, single-use context with restrictions & provenance.
06actexecute & receipt
verify capabilities, execute the permitted action & append a minimized receipt. memory writes remain proposals.
request → decision → disclosure → action → writeback
from argument to implementation.
the argument in plain language
02architecturethe system as purpose-bound flows & trust zones
03specificationobjects, lifecycles, policy & conformance
04implementationprofiles, adapters & deployment sequence
05codetested v0.2 contracts & a local proof profile
06demorun one synthetic request through policy, disclosure & receipt
start with the contract.
the published proof covers v0.2 contract validation, an encrypted local vault, four-state policy, scoped bundles, anchored receipts, a files adapter & a local-agent consumer. it does not claim production key custody or a portable signing suite.