vault zone
- source events
- claims & summaries
- identity bindings
- policies & keys
the map is split into readable protocol views. every node remains legible at the current viewport. the page scroll is the only navigation surface.
the vault remains authoritative. each consumer receives an expiring bundle with explicit capabilities & restrictions.
native source events retain origin, time, visibility & integrity
claims remain linked to source evidence, confidence & validity
private sources, policy, identity bindings & keys stay authoritative
requester, purpose, scope, recipient, expiry & approval produce one decision
the consumer receives only approved facts, capabilities & restrictions
tools & writeback remain bounded by the bundle, then create receipts
capture receipt → policy receipt → disclosure receipt → action receipt
local execution does not establish authorization. policy, recipient binding & expiry still apply.
authenticated client & delegated authority
declared task class & intended outcome
requested selectors, actions & sensitivity
model, agent, tool or application binding
expiry, retention & revocation state
human review when policy requires it
record the exact policy snapshot & inputs.
name the purpose, recipient, scope, actions & validity window
evaluate identity, policy, sensitivity, expiry & approval
issue the minimum approved facts, capabilities & restrictions
bind side effects to the granted capability set
record the outcome without copying private payloads
stage memory updates for review, supersession or rejection
the detailed SVG is a self-contained dark download. it carries its own palette, background & typography without an external stylesheet.