Architecture Overview

Three-Layer Trust Placement for Autonomous Trade

SeedCore separates advisory intelligence, runtime decision gating, and physical action. The trust boundary admits state transitions only after policy, authority lineage, and replayable evidence converge.

[Active RCT Runtime] [Target North Star]
Three-Layer Placement

The Durably Defined Trust Boundaries

SeedCore structures the autonomous environment into three distinct layers so custody-sensitive transitions cannot bypass policy and proof.

1. Brain / Intent (Top) Advisory Reasoning Plane

Humans and AI agents analyze and propose actions. This layer is entirely decoupled from execution authority; models cannot directly mutate state or control actuators.

2. SeedCore (Center) Stateless Policy Decision Point

Evaluates proposals against authorization policy and bounded context. On allow, it mints short-lived execution tokens and preserves the replay authority path.

3. Sandboxes / Reality (Bottom) Actuation & Evidence Emission

Robotic controllers, industrial actuators, and ledger systems execute authorized actions. Target trusted-edge profiles emit hardware-anchored telemetry for verification.

Authority Invariant

The Secure Lifecycle of a Governed Action

Every transaction or physical movement follows a strict, verification-first progression path.

Step A: PDP Check Synchronous Evaluation

The Policy Decision Point checks caller scope, bounded context, and required freshness evidence before minting execution authority.

Step B: ExecutionToken Scoped Bounded Authority

A cryptographically signed token is issued with explicit expiration, approved scope, and evidence obligations for the requested action.

Step C: Evidence Closure Physical-to-Digital Handshake

Telemetry fingerprints and economic identifiers converge under a signed EvidenceBundle before the transition can be treated as admissible.

Step D: Verifier Lockout Autonomous Verification

The Rust-based seedcore-verify path inspects the receipt. In the current RCT slice, mismatches drive fail-closed quarantine and downstream lockout markers.

RCT Slice vs North Star Target

Labeling the 2026 Execution Focus

Implemented Now Active RCT Restricted Custody Transfer (RCT)

Active runtime handles twin-event journaling, verifier lockout, and surfaces prior/result state bindings and causal references on opt-in workflows.

Next Extension Roadmap Multi-Agent Handoffs

Productizing dual-authorization release envelopes and expanding settlement classes (delivery, quarantine clearance) beyond RCT.

Durable Target Target Industrial Trusted Edge

Transitioning from Jetson prototype boards toward NVIDIA IGX Thor / T5000 edge profiles once secure boot, hardware identity, and replay-visible signatures are provisioned.

Supporting Assets

Technical Reference Links