CORE

Core shows how workspaces, Mancer packages, agents, orchestras, Archive, capabilities, evidence and authority boundaries connect. Real runs, prompts, model targets, workspace content and control stay private.

CapabilityPermissionAuthorityObjective
Explore the structure9 areas
01

What this is

An agent system with visible boundaries.

Core is a public architecture map, not a demo control room. It exposes contracts and workflows without opening private workspace state.

Architecture view

One map for the current system.

Core is the shared runtime. Workspaces and Mancer packages define work worlds, agents define roles, capabilities provide instruments, and orchestras compose the work. A human keeps final authority.

Agent Pool18contract agents
Orchestras2built-in workflows
Publish authority0for agents
Human gateONfinal approval
CURRENT STATE · 1.24.0

Core now describes the shared Lighthouse architecture.

The current architecture separates the shared Core, work worlds, capabilities, memory, boundaries and interface system.

BUILT INAnomancer · Romancer

Built-in work worlds running on the shared Core.

Mancer packageCodemancer · Romancer · Toimituskone

Mancer Package Runtime installs a new work world without name-specific Core code.

CapabilityNanomancer

Shared capability registry. Nanomancer is a deterministic, model-free analysis layer.

ArchiveArchive · Curator

Workspace-scoped memory trail, provenance and approval-bound persistence. No automatic model memory.

Boundary layersArtifact Boundary · Constitution Runtime · Human Approval · Model Router · Tool Broker

Artifact, constitution, approval, model and tool boundaries are separate contracts.

Interface systemVisual System · Dialog System · Responsive Workspace Navigation

Shared visual, dialog and responsive system for workspaces.

PUBLIC CORE V3

Capabilities are no longer a list. They form an execution architecture.

Capability Package Registry, Compute Runtime and Task Graph are now described directly from the public Core snapshot.

Capability Packages30anomancer-capability-package/v1
capability families6generated registry
LaskentamoottoriREADYcompute.tabular.v1
Final authorityHUMANexternal effects fail closed
01TaskProblemModel
02CapabilitiesCapability Registry
03Tehtävägraafianomancer-task-graph/v1
Readread-only
Computecompute
Reasoningreasoning
Proposalproposal
Approvalapproval
04TraceLighthouse Hands
05HUMANFinal authority
Laskentamoottori compute.tabular.v1

Bounded deterministic tabular compute. No network, shell or execution of user-supplied code.

CSV / TSV / JSON
READY
Data egress
NO
max rows
20000
Tehtävägraafi anomancer-task-graph/v1

The dependency graph creates topological stages and marks independent branches as parallel.

dependency aware
YES
parallel hints
YES
scheduler
bounded-executor
Multi-model layer COMING

Contracts exist, but the parallel ensemble runtime does not execute them yet.

model.comparemodel.disagreementmodel.mergeuncertainty.calibrate
Public glass wall ALLOWLIST

Public Core exposes architecture. Package permissions, raw contracts, provider configuration, prompts, workspace data and real run contents remain private.

prompts: privateworkspace: privateproviders: private
CAPABILITIES

Installed capability library

Grouped by the package families and routing classes declared by the packages themselves.

Data8
data.analyze READY
data.analyze
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
data.anomaly.detect READY
data.anomaly.detect
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
data.compare READY
data.compare
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
data.profile READY
data.profile
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
data.visualize READY
data.visualize
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
statistics.describe READY
statistics.describe
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
statistics.uncertainty READY
statistics.uncertainty
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
timeseries.analyze READY
timeseries.analyze
Version
1.0.0
routing
Compute
Adapter
compute.tabular.v1
Data egress
NO
Human gate
NO
Sources8
academic.search RUNTIME
academic.search
Version
1.0.0
routing
Read
Adapter
search.academic
Data egress
public-network
Human gate
NO
news.search RUNTIME
news.search
Version
1.0.0
routing
Read
Adapter
search.news
Data egress
public-network
Human gate
NO
source.bias.inspect READY
source.bias.inspect
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
source.crosscheck READY
source.crosscheck
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
source.primary.find READY
source.primary.find
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
source.rank READY
source.rank
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
source.recency.check READY
source.recency.check
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
source.search RUNTIME
source.search
Version
1.0.0
routing
Read
Adapter
search.web
Data egress
public-network
Human gate
NO
Markets6
market.liquidity READY
market.liquidity
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
market.risk READY
market.risk
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
market.scenario READY
market.scenario
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
market.sentiment READY
market.sentiment
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
market.snapshot READY
market.snapshot
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
market.volatility READY
market.volatility
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
Multi-model4
model.compare COMING
model.compare
Version
1.0.0
routing
Read
Adapter
model.ensemble.compare
Data egress
configured-provider
Human gate
NO
model.disagreement COMING
model.disagreement
Version
1.0.0
routing
Read
Adapter
model.ensemble.disagreement
Data egress
configured-provider
Human gate
NO
model.merge COMING
model.merge
Version
1.0.0
routing
Read
Adapter
model.ensemble.merge
Data egress
configured-provider
Human gate
NO
uncertainty.calibrate COMING
uncertainty.calibrate
Version
1.0.0
routing
Read
Adapter
model.ensemble.calibrate
Data egress
configured-provider
Human gate
NO
Research3
research.gap.detect READY
research.gap.detect
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
research.method.inspect READY
research.method.inspect
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
research.synthesize READY
research.synthesize
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
Reasoning1
comparison READY
comparison
Version
1.0.0
routing
Reasoning
Adapter
reasoning-proxy
Data egress
reasoner
Human gate
NO
IDENTITY

Agent Contract

A versioned role, tool surface and authority boundary. The agent does not grant itself permission.

FLOW

Orchestra Contract

The orchestra defines stage order and checkpoints. An individual agent is part of the workflow, not its owner.

TRACE

Run Receipt

A run can retain a hash and boundary trace without exposing raw input or model output.

Agent Registry

Agents are contracts, not hats.

The public view exposes role, model route, tool surface and authority boundary. Sessions, prompts and working memory are omitted.

Open Agent Registry 18
sourceSource Agent
e7ab9b185c2b…

Finds source candidates and research gaps on the public web. Cannot verify its own evidence.

Role
research-source-scout
Model route
research
Tool surface
Web Search
Human gate
YES
Publish
DENY
structureStructure Agent
0598309a1835…

Proposes article structure for the selected audience without changing evidence state.

Role
editorial-structure
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
writerWriter Agent
8bc514e9aeb3…

Writes and organises the draft but cannot promote a source candidate into verified evidence.

Role
draft-writer
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
criticCritic
66c73d2df5e0…

Finds weak assumptions, overconfident claims, missing counterevidence and audience problems.

Role
adversarial-review
Model route
critic
Tool surface
no tools
Human gate
YES
Publish
DENY
audienceAudience Adapter
4604ef474194…

Changes viewpoint and depth without changing the epistemic core of the text.

Role
audience-adapter
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
voiceVoice Editor
51ad5247467c…

Removes generic model language while preserving author voice and the audience contract.

Role
voice-editor
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
claimsClaim Watcher
64e56123f6cb…

Audits final prose claims and evidence links. Cannot verify sources.

Role
claim-auditor
Model route
critic
Tool surface
no tools
Human gate
YES
Publish
DENY
visualizationVisualisation Watcher
bbed85480141…

Proposes deterministic charts from verified data. Cannot invent data points.

Role
evidence-visualization
Model route
critic
Tool surface
no tools
Human gate
YES
Publish
DENY
packagePublication Package
4187749c9181…

Prepares publication metadata. The Evidence Layer and human audience contract remain locked.

Role
publication-packager
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-premisePremise
abe533b4f889…

Sharpens the story question, promise and scope without automatically saving the proposal.

Role
narrative-premise-editor
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-worldWorld Builder
a9dfeeb75b1b…

Builds rules, places and consequences under the premise and accepted canon.

Role
narrative-world-builder
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-characterCharacter Architect
c934f5aba882…

Deepens character goals, conflicts and voice while preserving accepted canon.

Role
narrative-character-architect
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-plotPlot Architect
ca3ba2e1b5cf…

Proposes structure, turning points and chapter plans without deleting existing chapters.

Role
narrative-plot-architect
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-sceneScene Writer
9d190ea59522…

Writes or continues a selected chapter using the project world, characters, plot, timeline and canon.

Role
narrative-scene-writer
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-continuityContinuity Watcher
a0a4cc0681c4…

Finds conflicts across canon, timeline, characters and chapters. Does not silently repair them.

Role
narrative-continuity-auditor
Model route
critic
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-voiceVoice Editor
94a948733701…

Refines chapter rhythm and voice without changing events, canon or character identity.

Role
narrative-voice-editor
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-criticCritic
542f47be5c0e…

Reviews tension, structure, character logic and exposition without automatic rewriting.

Role
narrative-adversarial-critic
Model route
critic
Tool surface
no tools
Human gate
YES
Publish
DENY
narrative-packageManuscript Package
4484bd578187…

Prepares manuscript order and export notes. Does not save, publish or export files.

Role
narrative-manuscript-packager
Model route
writer
Tool surface
no tools
Human gate
YES
Publish
DENY

Orchestra Registry

The same Core can run different workflows.

Anomancer Editorial and Romancer are peer built-in orchestras. Private custom orchestras are not part of the public snapshot.

Open orchestra stages 2
editorial / 1.0.0Anomancer Editorial
4ea599224d820827…

Built-in editorial orchestra.

01Source Agentresearch-source-scout
02Structure Agenteditorial-structure
03Writer Agentdraft-writer
04Criticadversarial-review
05Audience Adapteraudience-adapter
06Voice Editorvoice-editor
07Claim Watcherclaim-auditor
08Publication Packagepublication-packager
Evidence: candidate-never-equals-verifiedAudience: adapt-then-recheck-claimsHuman final authority: YES
narramancer / 1.0.0Romancer Story Orchestra
d1825c030b1f29b1…

Built-in story orchestra from premise to manuscript package.

01Premisenarrative-premise-editor
02World Buildernarrative-world-builder
03Character Architectnarrative-character-architect
04Plot Architectnarrative-plot-architect
05Scene Writernarrative-scene-writer
06Continuity Watchernarrative-continuity-auditor
07Voice Editornarrative-voice-editor
08Criticnarrative-adversarial-critic
09Manuscript Packagenarrative-manuscript-packager
Evidence: not-applicableAudience: author-intent-preservedHuman final authority: YES
02

How work moves

From proposal to verification to receipt.

Work moves through contracts, evidence boundaries, model routes and the Tool Broker. Autonomy does not mean unbounded authority.

Run chain

Work leaves a receipt, not a black box.

The public surface shows the receipt principle. Real run content, token usage and stage outputs stay inside private Core.

DEMO RECEIPTClaim Watcher
COMPLETED
Agent contract
claims / contractHash
Input
sha256: …
Output
sha256: …
Run parameters
PRIVATE · contract-bound
Publish authority
DENY
Human approval
REQUIRED
PUBLIC RECEIPT BOUNDARY

What can be verified?

  • which agent contract was used
  • the input and output hash trail
  • that execution stayed inside its authority boundary
  • that publication remained a human decision

Evidence Layer

A source candidate does not become evidence by chorus.

Source provenance, verification state and claim linkage stay separate. An agent may propose. A human may verify.

01Candidate

An agent finds a source candidate.

02Claim audit

The claim is linked to what the source actually supports.

03Human verification

A human accepts or rejects the source as evidence.

04Publish gate

Publication stops when required evidence is missing.

candidate ≠ verifiedconsensus ≠ independent verificationagent publish authority = 0

Model Routes

An agent and a model are different things.

The Agent Contract defines the task. The model route defines what class of model capability the task needs. Exact providers and model targets are private.

research1 agents · research

Source Agent

Public route requirements: json · web_search
Providers, model targets, fallback order and token limits remain inside the private Core.
writer12 agents · writer

Structure Agent · Writer Agent · Audience Adapter · Voice Editor · Publication Package · Premise · World Builder · Character Architect · Plot Architect · Scene Writer · Voice Editor · Manuscript Package

Public route requirements: json
Providers, model targets, fallback order and token limits remain inside the private Core.
critic5 agents · critic

Critic · Claim Watcher · Visualisation Watcher · Continuity Watcher · Critic

Public route requirements: json
Providers, model targets, fallback order and token limits remain inside the private Core.

Tool Surface

A tool is not permission to use a tool.

Tool requests pass through the server-side broker. Contract, risk and human-only boundaries are checked before execution.

BROKER ALLOWWeb Search

Contract agents: Source Agent

web.search · risk medium · policy server-side-fail-closed
HUMAN ONLYVerify Source

An agent cannot execute this action.

source.verify · risk high · policy server-side-fail-closed
HUMAN ONLYPublish

An agent cannot execute this action.

publication.publish · risk critical · policy server-side-fail-closed
HUMAN ONLYProject Write

An agent cannot execute this action.

project.write · risk critical · policy server-side-fail-closed
POLICY GATEDENY / HUMAN REQUIRED

Unknown or uncontracted tools are denied by default.

03

What stays bounded

Architecture is visible. Control is not.

Public Core exposes system boundaries, not private run content, workspace data or server configuration.

Budget & metering

The boundary is public. Tuning values are not.

Public Core states that runs are contract- and budget-bounded. Exact token limits, provider costs and actual usage remain private.

Contract budgetsPRIVATEpresent, but omitted from the snapshot
Runtime limitsPRIVATEserver-authoritative
Public audit surfaceRECEIPThashes + boundaries, no raw content

Workspace Boundary

One Core, multiple isolated workspaces.

The shared contract layer is separated from workspace-scoped state. The public snapshot exposes the boundary, not workspace names or content.

Anomancer, Romancer and Codemancer are public work-world types. Names and content of individual workspace instances remain private.

SHARED PLATFORMagent-contracts · tool-registry · model-router

Shared contract and policy layer

WORKSPACE SCOPEDruntime-profiles · custom-orchestras · runs · usage · artifact-store · content-adapter · output-adapter

Isolated agent-engine state

DEFAULTdefault

Legacy history remains without migration

MULTI-USER ACLNOT YET

Content scope defined

Application model

One machine, two depths of use.

Lighthouse is the application shell. Light mode routes the goal. The Workbench exposes Mancers, orchestras, agents, runs and approval boundaries when the user wants deeper control.

LIGHT MODE

Task first

Describe the goal in ordinary language. Lighthouse structures the task and proposes a workspace and method without filling the screen with machinery.

Open Light mode →
WORKBENCH

Expose the machinery

Select a Mancer and inspect orchestras, agents, runs, evidence, Archive and output boundaries. Anomancer is the editorial and publishing workspace.

Sign in to Workbench →
Lighthouseapplication shell Mancerworkspace / role Orchestraworkflow Agentbounded role Capabilityallowed action

Public / private

A glass wall is not an open door.

The architecture view can be public without turning private Lighthouse into a public control surface.

PUBLIC

/en/core

  • agent roles and contract structure
  • built-in orchestras
  • evidence and authority boundaries
  • public model-route and tool-surface structure
  • demo receipts and release provenance
Release provenance JSON →
PRIVATE

/lighthouse

  • real runs and run history
  • prompts, raw content and working memory
  • workspaces and custom orchestras
  • tool execution and approvals
  • server settings, model targets and secrets
Sign in to Lighthouse →
ROADMAP · CURRENT 1.24.0Open the Anomancer development map

Current state and direction

Lighthouse gathers the work worlds into one environment.

1.24.0 shifts the priority from adding isolated views to building one application shell. First the two Lighthouse modes and the Anomancer workspace migration become clear; new Mancers then grow on top of that structure.

LIGHTHOUSE application shellCORE general runtimeMANCERS work worldsAGENTS rolesCAPABILITIES instrumentsORCHESTRAS workflowsARCHIVE traceCONSTITUTION boundariesHUMAN authority
00
NOW · 1.24.0

Lighthouse convergence

1.24.0

One private entry point

/lighthouse is canonical. /admin and /lahetyskone remain compatibility routes, not user-facing product names.

1.24.x

Light mode + Workbench

Conversation and deep work share one session and one Core. Users change depth without changing mental models.

1.24.x

Anomancer becomes native

The existing editorial application is decomposed into Lighthouse modules. Publishing is separated from editorial work through Publishing Target adapters.

01
DONE · 1.18.3–1.18.7

From workbench to a verified release path

1.18.3–1.18.4

Codemancer + safe operations

The workbench, tests, diffs and plan-hash-bound human approval gates became one governed path.

1.18.6

Senior audit closure

The evidence truth model, accessibility matrix, release receipt and live-path verification moved into the release gate.

1.18.7

Public UI/UX polish

Dispatches, progressive evidence disclosure, Core typography, the Admin route and the Codemancer opening path were polished.

02
BACKLOG · after the Lighthouse shell

New work worlds

BACKLOG

Auditomancer

Software, agent, UI/UX, accessibility, security, evidence and semantic audits. First loop: Auditomancer → Codemancer → Nanomancer → human.

BACKLOG

Datamancer

Research question, hypotheses, dataset, methods, analysis, result, uncertainty and report. Result and interpretation remain separate objects.

BACKLOG

Stylemancer

Design system, typography, layout, assets, UI, CSS and visual regression as one artifact chain.

BACKLOG

Teachmancer

Goals, prerequisites, curriculum, exercises, assessment, feedback and progress from approved technical material.

BACKLOG

Ecomancer

Market, finance and risk analysis as observation → assumption → scenario → risk → counter-scenario → decision proposal → human.

BACKLOG

Cybomancer

Authorized security and adversarial testing only for owned, explicitly permitted, sandbox or CTF targets. No scope, no run.

03
1.25–1.30

Orchestration, memory, models and tools

1.25

Orchestra Registry V2

A stage may be an agent, plugin, tool, archive query, model, checkpoint, human approval or output adapter.

1.26

Context Gateway

Task → workspace policy → orchestra policy → Archive → selected memory → model. Context Inspector shows what a run may read before it starts.

1.27

Archive Graph

Project, Decision, Artifact, Run, Source, Audit and Dataset objects gain relations such as DERIVED_FROM, VALIDATED_BY and CONTRADICTS.

1.28

Multi-model Runtime

Multiple model families, per-stage routing, cost and token budgets, allowlists, health, timeout, fallback and model receipts.

1.29

Tool Sandbox

Capability Permission → Tool Broker → Sandbox → Receipt → Human approval. Tool authority never becomes an unrestricted shell.

1.30

Self-hosted Development Loop

Anomancer source → Codemancer → change proposal → tests → Nanomancer → Auditomancer → human review → apply. Governed, not autonomous.

04
1.31–1.35

The system starts observing itself

1.31

Cross-Mancer Workflows

Mancers exchange approved artifacts through Archive, Grant and Context Gateway without direct access to each other's internal state.

1.32

Command Palette / Core Search

Ctrl/Cmd + K opens workspaces, projects, runs, Archive, orchestras and settings from one global command surface.

1.33

Observability

Runs, latency, cost, models, errors, retries, tool calls, archive reads, context size, approval waits and regressions become visible.

1.34

Policy / Constitution Inspector

Before a run, users can inspect capabilities, denied actions, approval gates, Archive permissions and tool permissions.

1.35

Backup / Export / Restore

Projects, artifacts, Archive, receipts, constitutions, Mancer packages and settings export to JSON/Markdown/ZIP and return through validation and preview.

1.36

Lighthouse Constitution · Phase 8

The shared Lighthouse structure passes its final conformance gate: UI layers, boundaries, QA contracts and pre-release verification are checked as one coherent system.

05
1.4x → 2.0?

Personal stress testing first, multi-user only later

1.4x

Personal Hardening

Long-term use, real projects and audits, multiple model families, thousands of orchestra stages, Archive growth, backup/restore, cost calibration, permission boundaries and sandbox tests.

2.0?

Optional Multi-user Core

Only after the personal Core proves itself: tenant isolation, organizations, roles, secret vault, key and budget isolation, rate limits, abuse prevention, audit log, retention, deletion, export, billing and privacy.

NOW · 1.24 Lighthouse convergenceAnomancer migration + Publishing Targets1.25–1.36 infrastructure1.4x stress test2.0?