System Architecture

The Five Planes of TELHAR

A decoupled architecture designed so that reasoning models cannot grant themselves permissions, alter policy, or execute external actions unverified.

Memory Plane PROVEN

Mnḗmē

Continuous context, temporal indexing, and belief state. Never a global truth or identity authority.

Qdrant · pgvector · DEK telhar:v1:memory-envelope
Cognitive Plane IMPLEMENTED

Praxis & ARK

Parses intent, formulates plans, and deliberates. Proposes actions, but holds zero intrinsic execution authority.

TLA+ · Planner · LLM Router telhar:v1:execution-plan
Policy Plane (PDP) IMPLEMENTED

Foedus

Policy Decision Point. Evaluates covenants and deterministic rules prior to any state mutation in the world.

OPA · Rego · Fail-Closed telhar:v1:policy-decision
Evidence Plane PROVEN

Explorator & Refuto

Protected external discovery and independent falsification harness. "An agent cannot be judge of its own execution."

SSRF Guard · Immutable Ledger telhar:v1:evidence-event
Experience Plane IMPLEMENTED

Experience Platform

Multimodal perceptual projection over a singular core. The modality is an adapter, not a reimplementation.

Web · Desktop · Mobile · TUI telhar:v1:projection-model
Singular Chokepoint • Gateway Effect Gate

The 7 Controls of the Effect Gate

No model or agent has direct connectivity to actuators, APIs, or filesystem effects. Every action proposal crosses the 7 controls deterministically, terminating at the first DENY verdict.

1. Auth / Token
2. Tenant RLS
3. Rate Limit
4. Foedus PDP
5. Plan Hash
6. ARK Capability
7. Idempotence

1. The Architectural Premise

In typical LLM wrappers and contemporary autonomous agent platforms, the language model functions simultaneously as reasoning engine, storage gateway, session coordinator, and tool dispatcher. If the model hallucinates or succumbs to prompt injection, the entire security boundary collapses.

TELHAR separates these responsibilities into distinct architectural planes with orthogonal lifecycles and strict contract boundaries. Cognition proposes plans; Policy dictates legality; the Effect Gate enforces execution; and Evidence records immutable proof.

2. The Five Planes in Detail

Memory Plane — Mnḗmē (ai/mneme)

Mnḗmē is not a generic vector database. It is a governed memory plane maintaining persistent personal context across surfaces. It supports temporal decay, semantic indexing via pgvector and Qdrant, KMS-backed Data Encryption Keys (DEK), and Row-Level Security (RLS) isolation.

Invariants: Memory ≠ Truth · Memory ≠ Identity Provider · Contract: telhar:v1:memory-envelope

Cognitive Plane — Praxis & ARK (Agent Runtime Kernel)

The cognitive plane handles natural language interpretation, task decomposition, context assembly, and plan generation. It operates under the Agent Runtime Kernel (ARK), a finite state machine whose termination and non-livelock invariants have been formally model-checked in TLA+ (TLC 1.8.0, 149 distinct states).

Invariants: Cognition ≠ Authority · Output is data, never permission · Contract: telhar:v1:execution-plan

Policy Plane — Foedus (security/foedus)

The sole Policy Decision Point (PDP) of the architecture. Written in TypeScript and Open Policy Agent (Rego), Foedus evaluates explicit tenant covenants. Any access or action not explicitly permitted is rejected by default (fail-closed).

Invariants: Single-PDP Authority · Fail-Closed by default · Contract: telhar:v1:policy-decision

Evidence & Assurance Plane — Explorator & Refuto

Replaces blind trust with empirical proof. Explorator discovers external intelligence through fail-closed network egress guards and verifiable source provenance. Refuto provides the independent assurance harness that ensures agents never judge their own work.

Invariants: Evidence ≠ Claim · Append-only verification ledger · Contract: telhar:v1:evidence-event

Experience Plane — Experience Platform (platform/experience)

A single decision core projecting onto multiple perceptual modalities: Web (Next 15), Desktop (Tauri 2), Mobile (React Native), and Terminal (Rust TUI). A modality is treated as an adapter, not a reimplementation of business logic.

Invariants: FF-PROJECTION-NO-REVEAL · Contract: telhar:v1:projection-model

3. The Singular Effect Gate (Gateway Chokepoint)

All side-effects on the outside world — file writes, API calls, process spawning, shell execution, or remote communications — must flow through the **Effect Gate** in `core/gateway`. The gate enforces 7 sequential controls:

  1. Authentication & Identity: Cryptographic verification of the calling principal token (RS256).
  2. Tenant Isolation: Validation of workspace boundary and tenant tenancy keys.
  3. Rate & Budget Limiting: Fail-closed token/cost ceilings. Overrun stops execution immediately.
  4. Policy PDP Evaluation: Synchronous Foedus OPA check. Non-ALLOW responses terminate the call.
  5. Approval Plan Binding: Verification of single-use hash (approvedSetHash) tied to the user turn.
  6. Capability Token Attenuation: Verification that the capability was derived in kernel without escalation.
  7. Idempotency Validation: Checking deduplication caches to prevent duplicate external side-effects.
Rule: Any failure at steps 1–7 results in an immediate fail-closed denial. No tool is executed on partial passes.

4. Ecosystem Topology: The 10 Spine Services

While the TELHAR GitLab organization encompasses 51 modular projects distributed across 12 domain subgroups, the live runtime collapses onto 10 foundational spine services that enforce mathematical and architectural invariants:

01. core/gateway Rust Axum execution gateway enforcing the 7 controls of the Effect Gate.
02. core/agent-kernel (ARK) Rust FSM model-checked in TLA+ (149 states, zero deadlocks).
03. security/foedus Policy Decision Point evaluating deterministic OPA/Rego covenants.
04. ai/explorator Protected web intelligence with fail-closed SSRF egress (133k tested IPs).
05. ai/mneme Continuous memory plane with DEK/FTS and KMS-backed envelope encryption.
06. ai/via Frontier Fabric Router with formally verified fallback policies.
07. ai/praxis-api Cognitive agent runtime managing intent parsing and execution planning.
08. core/sso Platform-wide identity authority implementing OIDC 2.1 / PKCE with JWT.
09. ai/aesthesis Multimodal perceptual physics engine grounded in physical equations.
10. product/telhar-cli & platform/experience Human interaction surfaces: high-performance Rust TUI and multidevice Web.

5. Agent Run Cancellation: Invariant of Human Authority

In TELHAR, human agency is an operational invariant, not an aspiration. When a person requests cancellation of an autonomous agent turn:

  • Authority: Only the sovereign person may initiate cancellation via authenticated HTTP (/v1/agent-runs/:runId/cancelar).
  • Zero Model Authority: The AI model has zero capacity to decide, delay, or prevent its own cancellation.
  • Deterministic Propagation: AgentRunService marks cancelRequestedAt idempotently and routes the order through the bridge gateway directly to telhar-cli (serve.rs).
  • Execution Fence: Any action currently in-flight finishes its bounded step, but no subsequent acts are dispatched. The run seals in immutable CANCELLED state.

6. Contract Authority & Canonical Schemas

TELHAR rejects implicit contracts and ad-hoc JSON payloads. The system is governed by 29 formal JSON Schemas located in contracts/schemas, versioned under strict SemVer and serialized deterministically per RFC-8785 (Canonical JSON).

7. Target Topology & Governance Enforcement

The 5–10 year target architecture (Document 11) is driven by radical consolidation: collapse to the real. The architecture enforces a single enforcement point without bypass ingress paths:

Cloudflare (TLS Ingress) → Gateway (Rust PEP · RS256/JWKS · Single Chokepoint) ↓ Foedus (PDP · OPA/Rego) + Praxis (API / Cognition) ↓ [Executor: Model Plane] · [Via: Routing & Budget] · [Mnḗmē: RLS Memory]

Identity & Token Invariants

Single IdP (core/sso), RS256/JWKS exclusively, zero HMAC/HS256 side-doors. Service-to-service communication relies on mTLS or signed service tokens.

Tenancy & Row-Level Security

Tenancy is not enforced by fragile manual WHERE clauses. Postgres Row-Level Security (RLS) acts as a cryptographic backstop under every query in Mnḗmē.