sierra catalina

architecture / protocol system map

the whole system.
one explicit boundary.

private sources remain inside the vault. approved context crosses through policy as an expiring, recipient-bound bundle; every operation leaves a receipt.

00 / protocol overview

the exchange at a glance.

six recorded steps move context from capture to bounded action. receipts record outcomes & route proposed writeback through policy.

context layer architecture: capture, normalize, vault, decide, bundle & act, followed by a receipt & policy-bound writeback context layer architecture: capture, normalize, vault, decide, bundle & act, followed by a receipt & policy-bound writeback
capture, policy, scoped disclosure, action, receipts & writeback in one exchange.view full-size diagram ↗

01 / primary exchange

purpose-bound context flow.

the vault remains authoritative. each consumer receives an expiring bundle with explicit capabilities & restrictions.

  1. 01capture

    native source events retain origin, time, visibility & integrity

  2. 02normalize

    claims remain linked to source evidence, confidence & validity

  3. 03vault

    private sources, policy, identity bindings & keys stay authoritative

  4. 04decide

    requester, purpose, scope, recipient, expiry & approval produce one decision

  5. 05bundle

    the consumer receives only approved facts, capabilities & restrictions

  6. 06act

    tools & writeback remain bounded by the bundle, then create receipts

evidence

capture receipt → policy receipt → disclosure receipt → action receipt

02 / trust zones

three zones. one explicit crossing.

user controlled

vault zone

  • source events
  • claims & summaries
  • identity bindings
  • policies & keys

decision boundary

controlled exchange

  • request validation
  • policy evaluation
  • semantic proxy
  • bundle issuer

separate authority

consumer zone

  • apps & agents
  • models & tools
  • discovery systems
  • interface surfaces

local execution does not establish authorization. policy, recipient binding & expiry still apply.

03 / control plane

the decision is inspectable.

requester

authenticated client & delegated authority

purpose

declared task class & intended outcome

scope

requested selectors, actions & sensitivity

recipient

model, agent, tool or application binding

time

expiry, retention & revocation state

approval

human review when policy requires it

policy resultallow / reduce / request approval / deny

the receipt preserves inputs, the policy snapshot & reason codes.

04 / lifecycle

each state has a receipt.

  1. request

    name the purpose, recipient, scope, actions & validity window

  2. decision

    evaluate identity, policy, sensitivity, expiry & approval

  3. bundle

    issue the minimum approved facts, capabilities & restrictions

  4. action

    bind side effects to the granted capability set

  5. receipt

    record the outcome without copying private payloads

  6. writeback

    stage memory updates for review, supersession or rejection

protocol reference

the exchange in one map.

download a portable summary of the request, decision, disclosure, action & writeback lifecycle, or read the specification for the complete contract.