1. The Architectural Premise
In typical LLM wrappers and contemporary autonomous agent platforms, the language model functions simultaneously as reasoning engine, storage gateway, session coordinator, and tool dispatcher. If the model hallucinates or succumbs to prompt injection, the entire security boundary collapses.
TELHAR separates these responsibilities into distinct architectural planes with orthogonal lifecycles and strict contract boundaries. Cognition proposes plans; Policy dictates legality; the Effect Gate enforces execution; and Evidence records immutable proof.
2. The Five Planes in Detail
Memory Plane — Mnḗmē (ai/mneme)
Mnḗmē is not a generic vector database. It is a governed memory plane maintaining persistent personal context across surfaces. It supports temporal decay, semantic indexing via pgvector and Qdrant, KMS-backed Data Encryption Keys (DEK), and Row-Level Security (RLS) isolation.
Cognitive Plane — Praxis & ARK (Agent Runtime Kernel)
The cognitive plane handles natural language interpretation, task decomposition, context assembly, and plan generation. It operates under the Agent Runtime Kernel (ARK), a finite state machine whose termination and non-livelock invariants have been formally model-checked in TLA+ (TLC 1.8.0, 149 distinct states).
Policy Plane — Foedus (security/foedus)
The sole Policy Decision Point (PDP) of the architecture. Written in TypeScript and Open Policy Agent (Rego), Foedus evaluates explicit tenant covenants. Any access or action not explicitly permitted is rejected by default (fail-closed).
Evidence & Assurance Plane — Explorator & Refuto
Replaces blind trust with empirical proof. Explorator discovers external intelligence through fail-closed network egress guards and verifiable source provenance. Refuto provides the independent assurance harness that ensures agents never judge their own work.
Experience Plane — Experience Platform (platform/experience)
A single decision core projecting onto multiple perceptual modalities: Web (Next 15), Desktop (Tauri 2), Mobile (React Native), and Terminal (Rust TUI). A modality is treated as an adapter, not a reimplementation of business logic.
3. The Singular Effect Gate (Gateway Chokepoint)
All side-effects on the outside world — file writes, API calls, process spawning, shell execution, or remote communications — must flow through the **Effect Gate** in `core/gateway`. The gate enforces 7 sequential controls:
- Authentication & Identity: Cryptographic verification of the calling principal token (RS256).
- Tenant Isolation: Validation of workspace boundary and tenant tenancy keys.
- Rate & Budget Limiting: Fail-closed token/cost ceilings. Overrun stops execution immediately.
- Policy PDP Evaluation: Synchronous Foedus OPA check. Non-ALLOW responses terminate the call.
- Approval Plan Binding: Verification of single-use hash (
approvedSetHash) tied to the user turn. - Capability Token Attenuation: Verification that the capability was derived in kernel without escalation.
- Idempotency Validation: Checking deduplication caches to prevent duplicate external side-effects.
4. Ecosystem Topology: The 10 Spine Services
While the TELHAR GitLab organization encompasses 51 modular projects distributed across 12 domain subgroups, the live runtime collapses onto 10 foundational spine services that enforce mathematical and architectural invariants:
5. Agent Run Cancellation: Invariant of Human Authority
In TELHAR, human agency is an operational invariant, not an aspiration. When a person requests cancellation of an autonomous agent turn:
- Authority: Only the sovereign person may initiate cancellation via authenticated HTTP (
/v1/agent-runs/:runId/cancelar). - Zero Model Authority: The AI model has zero capacity to decide, delay, or prevent its own cancellation.
- Deterministic Propagation:
AgentRunServicemarkscancelRequestedAtidempotently and routes the order through the bridge gateway directly totelhar-cli(serve.rs). - Execution Fence: Any action currently in-flight finishes its bounded step, but no subsequent acts are dispatched. The run seals in immutable
CANCELLEDstate.
6. Contract Authority & Canonical Schemas
TELHAR rejects implicit contracts and ad-hoc JSON payloads. The system is governed by 29 formal JSON Schemas located in contracts/schemas, versioned under strict SemVer and serialized deterministically per RFC-8785 (Canonical JSON).
7. Target Topology & Governance Enforcement
The 5–10 year target architecture (Document 11) is driven by radical consolidation: collapse to the real. The architecture enforces a single enforcement point without bypass ingress paths:
Identity & Token Invariants
Single IdP (core/sso), RS256/JWKS exclusively, zero HMAC/HS256 side-doors. Service-to-service communication relies on mTLS or signed service tokens.
Tenancy & Row-Level Security
Tenancy is not enforced by fragile manual WHERE clauses. Postgres Row-Level Security (RLS) acts as a cryptographic backstop under every query in Mnḗmē.