Architecture

Boundaries first

Diskarte’s major architectural boundaries are either enforced in implementation, established in approved doctrine, or explicitly tracked as implementation awaiting ratification. This page is the public map.

Runtime anatomy

A native Desktop and an Organization Console speak to one Platform API. Behind it, a governed core: a pure kernel, orchestration, governance gates, judgment, memory, and projections — with cognition and substrate held at the edges behind ports. Deployment simplifies; architecture does not: the whole runtime can run as one local binary with every boundary intact.

Seven kernel primitives

Actor, Role, Boundary, Decision, WorkOrder, Artifact, Evaluation — and deliberately no eighth. The kernel decides all authority and never reasons, never names a substrate, and never declares completion without Evaluation.

Authority is computed

Authority(actor, context) = Role ∩ Boundary, evaluated at the moment of authorization and never stored. Three verdicts: permitted, requires-approval, forbidden. Routing is dispatch of already-authorized work — a second “who may act” concept is the failure mode the kernel refuses.

The governed spine

Boundary → Authorized Intent → WorkOrder. No governed side effect occurs except through this spine, and no work completes except through Evaluation. Authorized Intent is derived, never persisted.

Cognition reasons; it never governs

The cognition interior lives behind a single Produce/Judge port, structurally unable to touch storage, authority, identity, or lifecycle — enforced by import guards that fail the build, not by review comments. Its output is always untrusted, always attributed, and enters the organization only through the governed door.

Two memories, never conflated

Canonical memory — the set of ratified Artifacts — reconstructs the organization. Retrieval memory — embeddings and indexes — accelerates cognition and is rebuildable at any time. A vector index that becomes a source of truth is a second system of record; the split exists to prevent exactly that.

Identity is not authority

An identity provider owns one truth: this human controls this identity. Provider claims arrive as evidence and never become authority; Diskarte-owned sessions, membership, and mandates are the record — granted and revoked only by Runtime governance. Four proofs, four granters: possession, identity, legitimacy, authority.

Evidence → justified model → ratification → canon

The runtime operates on exactly two kinds of thing: observable evidence and governed commitment. Evidence is partial and never self-certifying; the justified model carries confidence and provenance; only a human ratification writes canon. The moment evidence drives governance it becomes a target — so no direct edge from evidence to canon exists.

Substrate abstraction

Practices declare abstract capability requirements. Governed bindings resolve them to providers under an organization-owned policy. Five deployment profiles — Local and Diskarte Managed adoptable today; Hybrid and Cloud architecturally defined; Air-Gapped deferred by ruling. Migration is a policy amendment, never a restart, and model identity travels only as provenance.

Operations outside authority

A separate Operations Platform provisions installations, issues setup codes, manages releases and managed appliances. Its database access is allowlisted away from every Runtime store: Diskarte-the-vendor holds no authority, read, or write inside any organization — structurally, not as policy.

Federation and artifact boundaries

The system is a federation of repositories where every cross-repo dependency is a versioned published artifact — never a source import. The Desktop is the composition point: it pins runtime and UI by digest and fails closed on mismatch. Architectural violations become build failures.

Cognition reasons. It never governs.

The kernel decides all authority and never reasons; cognition reasons and never decides. The seam between them is the product.

Help shape the next stage.

Apply as a design partner to test these boundaries against real organizational needs.

Alpha signup opens shortly.

The list is not accepting submissions yet. We would rather show you nothing than a form that quietly drops your address.