consequence clearing for autonomous AI systems — a premise changes, the fleet is planned, delegated, challenged, governed and corrected, and every step leaves evidence
No credential required. Replays a real, captured, zero-model mission trace — recon through governance through knowledge distillation — computed once by the exact same pipeline "Run autonomous mission" below uses, so a judge sees the full chain immediately with nothing to configure. No token is requested or sent by this button, and nothing it does can mutate real state.
every model string this system pins, joined to what a real call actually did — model IDs from lib/config.py, statuses from evidence/models/verification-*.json, never from a hardcoded list on this page. A model that has not been exercised says so.
all three read the same grounded brief, built from the checkpoints this mission actually persisted (GET /api/media/mission/{id}/brief returns the exact input, so it can be checked against the checkpoints themselves). Each card plays a committed render immediately and can also make a live call when a credential is present.
one real Veo and one real Lyria generation ran against live Vertex AI on 2026-08-21 (evidence/models/verification-20260821T031634Z.json). Those files are gitignored model output, so they appear here only where someone has actually put them — never re-triggered to render this panel.
computed from the objective · provenance is set by the code path that actually ran, never claimed
every number below comes from the retrieval that actually informed this plan, read back from its PLAN checkpoint. The counts are the point: a system that “retrieves” everything it stored has not retrieved anything. A recalled record can raise a risk class or ask for a read-only check — it has no field capable of granting scope (recall/guard.py).
the extractor settles a contradiction by RECENCY; a separately-scoped agent (fleet_reconciler) re-derives it from AUTHORITY. Where they agree the premise is settled. Where they disagree nothing is decided here — the claim is DISPUTED, the dispute raises the price of every later action, and it reaches the human.
The mission paused after isolating the agent. Approving resumes the SAME repair → re-mint → re-validate chain the automatic path uses; the original Gateway refusal is never overturned either way — approval only authorises a new, narrower request to be independently re-checked.
every node below is read from THIS mission's own report and stage list — nothing here is a separate claim, it is the same data above, in the order it actually happened. A node is dimmed when this mission did not reach it.
categorical, never a score — see the concept map for why
what a resume would actually see, and why
the one place this system changes anything outside its own process — idempotent, reversible, and re-read to verify
six identities with their own principals and bounded scope — served from the same constants the registry enforces. Verify it yourself: GET /api/architecture/proof
move a signal, watch every price change. Computed in warrant/economics.py, which cannot reach a model
the question this product is named after, asked of an AGENT ACTION. Every number below is a real traversal of the committed reverse index (spine/cascade.py) over the premises the recon agent actually parsed — zero model calls. Drive it yourself: GET /api/command-os/consequence-preview?subject=supplier_K&predicate=lead_time_days&value=20
every feature below carries its own honest status — nothing here claims to be live that is not
historical mission state, reconstructed from real checkpoints — not a literal reversal of time, a replay of what was actually persisted. Loads with this page; the most recent mission opens on its own.
every stage above calls a real engine one layer down · every status label is served by /api/command-os/status, a second independently queryable source that must agree with this page or this page is wrong
how the agent BEHAVED, not just what it returned — seven deterministic criteria computed from what the mission measured, never from a model's account of itself
click a card to open its detail · Esc returns here
agentic immune core — scores and logs every real Gateway decision; it observes agent execution state and intended tool actions before they cross the security boundary, it does not gate them. Card 2's Gateway remains the one choke point.
Every event above is a real, already-happened call to tower.gateway.evaluate_gateway, scored by a fixed, deterministic weight table (hyperion/risk.py) and logged append-only. Hyperion adds no second authority path — the Gateway's four ordered checks are untouched.
MCP tool-call guarding, live Model Armor enforcement, sandboxed execution, and automated quarantine/recovery are architecture only in this build — not implemented, not simulated. See hyperion/DESIGN.md for the full, honest accounting.
deterministic, decaying, capability-scoped authority — minted only from countersigned, human-validated outcomes. Nobody hands it over; nobody can hand it on.
Balance is a pure integer fold over an append-only ledger (MINT · BURN · SPEND · DECAY · CHALLENGE) — never a single global number, always per capability × risk class.
Insufficient warrant does not retry. The Gateway refuses at WARRANT_INSUFFICIENT, before any work, and the case routes to a human — the live fold, no cache, visible on the very next call.
executable registry · deterministic gateway · decision memory · durable runtime · observability
Append-only, causal chain: case → premise → decision → agent action → human decision → outcome → future consequence. Not a vector store — tower/memory.py answers "what happened because of X?" by walking the chain.
Cloud Trace carries the full reasoning chain as one root span, including the Gateway's router branches. See evidence/observability/.
independent verifier · Gemma, a family separate from the judging side · gates warrant minting
ZERO-TRUST AUTONOMOUS AGENT FLEET — an adaptive operating architecture governing capabilities, tools, execution, behavior, security, memory and recovery across a fleet of agents.
Singularity-Mesh is a Zero-Trust Autonomous Agent Fleet where agents plan tasks, use governed tools, execute untrusted workloads inside isolated sandboxes, communicate through controlled interfaces, detect security threats and recover from failures.
Sentinel Shield is the Policy Enforcement Agent. The Orchestrator's loop is Plan → Delegate → Monitor → Validate → Recover. The Worker Fleet is a set of specialized, isolated execution workers.
Dynamic task-bound capability identity
An agent does not receive unlimited permanent power. The system continuously determines what this agent is allowed to do right now, for this task, under this risk context.
Do not just inspect what the agent says. Inspect what the agent is becoming.
Connects to HYPERION-ZERO conceptually — both implement a form of agent immunity — without merging their cards or interfaces. See "Relationship with Hyperion-Zero" below.
Input Immunity screens for prompt injection, tool poisoning, malicious requests and suspicious instructions, before any dangerous tool executes.
Parallel execution · isolation · fault tolerance · specialization · scaling.
LLM-generated code is not automatically trusted. It runs isolated, and cleans up after.
No sandboxed execution environment exists in this repository. Any recovery/controller logic described elsewhere on this page is application-level orchestration around a sandbox, not evidence of one running.
MCP = Model Context Protocol — standardized agent-to-tool/data communication, so an agent never gets direct, unrestricted database access.
LLM ≠ direct database administrator. The agent accesses governed capabilities/data through the approved interface only.
Threat: prompt injection / malicious tool request. Result: BLOCK · LOG · ALERT · NO TOOL EXECUTION. No Model Armor API is called anywhere in this repository — this is architecture, not a live integration.
"No uncontrolled agent interaction bypasses the controlled entry point."
"Every agent has an identity. Every identity has minimum permissions."
Represented as an application-level recovery controller wrapped around a sandbox — DETECT and BLOCK are live decisions from Behavioral DNA and Capability Genome above; ISOLATE through SUCCESS are architecture only.
Each component carries its own identity, capability, policy, state and communication channel — a true multi-agent architecture, not one model wearing different hats.
"More autonomy without governance creates more risk."
cross-cutting: IAM · MEMORY · OBSERVABILITY · BEHAVIORAL DNA · RECOVERY CONTROLLER
Event fields: timestamp · agent_id · session_id · task_id · tool · decision · latency · security_result · worker_id
No mesh events logged yet — run a Capability Genome or Behavioral DNA probe above, or reload after one has run elsewhere.
"This is not a chatbot. This is an autonomous multi-agent system."
"We don't just inspect what an agent says. We govern what an agent is allowed to do and detect what the agent is becoming."
Prompt security protects the request. Capability governance protects the action. Behavioral immunity protects the agent itself.
HYPERION-ZERO: agent runtime immune/security control layer over Card 2's real Gateway.
SINGULARITY-MESH: broader autonomous agent fleet architecture and governed-autonomy framework. Capability Genome and Behavioral DNA are this card's own new innovation layer.
The two systems complement each other conceptually but share no code path, no collection and no API route — Hyperion's card and endpoints are untouched by this card's existence.
Every claim on this page is labelled LIVE (a real, deterministic, tested engine — Capability Genome, Behavioral DNA, and their append-only event log), ARCHITECTURE (documented design, not a running system in this repository), or DEMO/SIMULATION (a scripted scenario used to exercise a live engine). See singularity/DESIGN.md for the full accounting.