CORE
Core shows how workspaces, Mancer packages, agents, orchestras, Archive, capabilities, evidence and authority boundaries connect. Real runs, prompts, model targets, workspace content and control stay private.
Explore the structure9 areas
What this is
An agent system with visible boundaries.
Core is a public architecture map, not a demo control room. It exposes contracts and workflows without opening private workspace state.
Architecture view
One map for the current system.
Core is the shared runtime. Workspaces and Mancer packages define work worlds, agents define roles, capabilities provide instruments, and orchestras compose the work. A human keeps final authority.
Core now describes the shared Lighthouse architecture.
The current architecture separates the shared Core, work worlds, capabilities, memory, boundaries and interface system.
Built-in work worlds running on the shared Core.
Mancer Package Runtime installs a new work world without name-specific Core code.
Shared capability registry. Nanomancer is a deterministic, model-free analysis layer.
Workspace-scoped memory trail, provenance and approval-bound persistence. No automatic model memory.
Artifact, constitution, approval, model and tool boundaries are separate contracts.
Shared visual, dialog and responsive system for workspaces.
Capabilities are no longer a list. They form an execution architecture.
Capability Package Registry, Compute Runtime and Task Graph are now described directly from the public Core snapshot.
read-onlycomputereasoningproposalapprovalBounded deterministic tabular compute. No network, shell or execution of user-supplied code.
- CSV / TSV / JSON
- READY
- Data egress
- NO
- max rows
- 20000
The dependency graph creates topological stages and marks independent branches as parallel.
- dependency aware
- YES
- parallel hints
- YES
- scheduler
- bounded-executor
Contracts exist, but the parallel ensemble runtime does not execute them yet.
model.comparemodel.disagreementmodel.mergeuncertainty.calibratePublic Core exposes architecture. Package permissions, raw contracts, provider configuration, prompts, workspace data and real run contents remain private.
prompts: privateworkspace: privateproviders: privateInstalled capability library
Grouped by the package families and routing classes declared by the packages themselves.
Data8
data.analyze
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
data.anomaly.detect
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
data.compare
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
data.profile
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
data.visualize
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
statistics.describe
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
statistics.uncertainty
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
timeseries.analyze
READY
- Version
- 1.0.0
- routing
- Compute
- Adapter
- compute.tabular.v1
- Data egress
- NO
- Human gate
- NO
Sources8
academic.search
RUNTIME
- Version
- 1.0.0
- routing
- Read
- Adapter
- search.academic
- Data egress
- public-network
- Human gate
- NO
news.search
RUNTIME
- Version
- 1.0.0
- routing
- Read
- Adapter
- search.news
- Data egress
- public-network
- Human gate
- NO
source.bias.inspect
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
source.crosscheck
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
source.primary.find
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
source.rank
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
source.recency.check
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
source.search
RUNTIME
- Version
- 1.0.0
- routing
- Read
- Adapter
- search.web
- Data egress
- public-network
- Human gate
- NO
Markets6
market.liquidity
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
market.risk
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
market.scenario
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
market.sentiment
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
market.snapshot
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
market.volatility
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
Multi-model4
model.compare
COMING
- Version
- 1.0.0
- routing
- Read
- Adapter
- model.ensemble.compare
- Data egress
- configured-provider
- Human gate
- NO
model.disagreement
COMING
- Version
- 1.0.0
- routing
- Read
- Adapter
- model.ensemble.disagreement
- Data egress
- configured-provider
- Human gate
- NO
model.merge
COMING
- Version
- 1.0.0
- routing
- Read
- Adapter
- model.ensemble.merge
- Data egress
- configured-provider
- Human gate
- NO
uncertainty.calibrate
COMING
- Version
- 1.0.0
- routing
- Read
- Adapter
- model.ensemble.calibrate
- Data egress
- configured-provider
- Human gate
- NO
Research3
research.gap.detect
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
research.method.inspect
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
research.synthesize
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
Reasoning1
comparison
READY
- Version
- 1.0.0
- routing
- Reasoning
- Adapter
- reasoning-proxy
- Data egress
- reasoner
- Human gate
- NO
Agent Contract
A versioned role, tool surface and authority boundary. The agent does not grant itself permission.
Orchestra Contract
The orchestra defines stage order and checkpoints. An individual agent is part of the workflow, not its owner.
Run Receipt
A run can retain a hash and boundary trace without exposing raw input or model output.
Agent Registry
Agents are contracts, not hats.
The public view exposes role, model route, tool surface and authority boundary. Sessions, prompts and working memory are omitted.
Open Agent Registry 18
e7ab9b185c2b…Finds source candidates and research gaps on the public web. Cannot verify its own evidence.
- Role
research-source-scout- Model route
- research
- Tool surface
- Web Search
- Human gate
- YES
- Publish
- DENY
0598309a1835…Proposes article structure for the selected audience without changing evidence state.
- Role
editorial-structure- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
8bc514e9aeb3…Writes and organises the draft but cannot promote a source candidate into verified evidence.
- Role
draft-writer- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
66c73d2df5e0…Finds weak assumptions, overconfident claims, missing counterevidence and audience problems.
- Role
adversarial-review- Model route
- critic
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
4604ef474194…Changes viewpoint and depth without changing the epistemic core of the text.
- Role
audience-adapter- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
51ad5247467c…Removes generic model language while preserving author voice and the audience contract.
- Role
voice-editor- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
64e56123f6cb…Audits final prose claims and evidence links. Cannot verify sources.
- Role
claim-auditor- Model route
- critic
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
bbed85480141…Proposes deterministic charts from verified data. Cannot invent data points.
- Role
evidence-visualization- Model route
- critic
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
4187749c9181…Prepares publication metadata. The Evidence Layer and human audience contract remain locked.
- Role
publication-packager- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
abe533b4f889…Sharpens the story question, promise and scope without automatically saving the proposal.
- Role
narrative-premise-editor- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
a9dfeeb75b1b…Builds rules, places and consequences under the premise and accepted canon.
- Role
narrative-world-builder- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
c934f5aba882…Deepens character goals, conflicts and voice while preserving accepted canon.
- Role
narrative-character-architect- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
ca3ba2e1b5cf…Proposes structure, turning points and chapter plans without deleting existing chapters.
- Role
narrative-plot-architect- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
9d190ea59522…Writes or continues a selected chapter using the project world, characters, plot, timeline and canon.
- Role
narrative-scene-writer- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
a0a4cc0681c4…Finds conflicts across canon, timeline, characters and chapters. Does not silently repair them.
- Role
narrative-continuity-auditor- Model route
- critic
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
94a948733701…Refines chapter rhythm and voice without changing events, canon or character identity.
- Role
narrative-voice-editor- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
542f47be5c0e…Reviews tension, structure, character logic and exposition without automatic rewriting.
- Role
narrative-adversarial-critic- Model route
- critic
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
4484bd578187…Prepares manuscript order and export notes. Does not save, publish or export files.
- Role
narrative-manuscript-packager- Model route
- writer
- Tool surface
- no tools
- Human gate
- YES
- Publish
- DENY
0 agents
Orchestra Registry
The same Core can run different workflows.
Anomancer Editorial and Romancer are peer built-in orchestras. Private custom orchestras are not part of the public snapshot.
Open orchestra stages 2
4ea599224d820827…Built-in editorial orchestra.
candidate-never-equals-verifiedAudience: adapt-then-recheck-claimsHuman final authority: YESd1825c030b1f29b1…Built-in story orchestra from premise to manuscript package.
not-applicableAudience: author-intent-preservedHuman final authority: YESHow work moves
From proposal to verification to receipt.
Work moves through contracts, evidence boundaries, model routes and the Tool Broker. Autonomy does not mean unbounded authority.
Run chain
Work leaves a receipt, not a black box.
The public surface shows the receipt principle. Real run content, token usage and stage outputs stay inside private Core.
- Agent contract
claims / contractHash- Input
sha256: …- Output
sha256: …- Run parameters
- PRIVATE · contract-bound
- Publish authority
- DENY
- Human approval
- REQUIRED
What can be verified?
- which agent contract was used
- the input and output hash trail
- that execution stayed inside its authority boundary
- that publication remained a human decision
Evidence Layer
A source candidate does not become evidence by chorus.
Source provenance, verification state and claim linkage stay separate. An agent may propose. A human may verify.
An agent finds a source candidate.
The claim is linked to what the source actually supports.
A human accepts or rejects the source as evidence.
Publication stops when required evidence is missing.
Model Routes
An agent and a model are different things.
The Agent Contract defines the task. The model route defines what class of model capability the task needs. Exact providers and model targets are private.
researchSource Agent
json · web_searchwriterStructure Agent · Writer Agent · Audience Adapter · Voice Editor · Publication Package · Premise · World Builder · Character Architect · Plot Architect · Scene Writer · Voice Editor · Manuscript Package
jsoncriticCritic · Claim Watcher · Visualisation Watcher · Continuity Watcher · Critic
jsonTool Surface
A tool is not permission to use a tool.
Tool requests pass through the server-side broker. Contract, risk and human-only boundaries are checked before execution.
Contract agents: Source Agent
web.search · risk medium · policy server-side-fail-closedAn agent cannot execute this action.
source.verify · risk high · policy server-side-fail-closedAn agent cannot execute this action.
publication.publish · risk critical · policy server-side-fail-closedAn agent cannot execute this action.
project.write · risk critical · policy server-side-fail-closedUnknown or uncontracted tools are denied by default.
What stays bounded
Architecture is visible. Control is not.
Public Core exposes system boundaries, not private run content, workspace data or server configuration.
Budget & metering
The boundary is public. Tuning values are not.
Public Core states that runs are contract- and budget-bounded. Exact token limits, provider costs and actual usage remain private.
Workspace Boundary
One Core, multiple isolated workspaces.
The shared contract layer is separated from workspace-scoped state. The public snapshot exposes the boundary, not workspace names or content.
Anomancer, Romancer and Codemancer are public work-world types. Names and content of individual workspace instances remain private.
agent-contracts · tool-registry · model-routerShared contract and policy layer
runtime-profiles · custom-orchestras · runs · usage · artifact-store · content-adapter · output-adapterIsolated agent-engine state
defaultLegacy history remains without migration
NOT YETContent scope defined
Application model
One machine, two depths of use.
Lighthouse is the application shell. Light mode routes the goal. The Workbench exposes Mancers, orchestras, agents, runs and approval boundaries when the user wants deeper control.
Task first
Describe the goal in ordinary language. Lighthouse structures the task and proposes a workspace and method without filling the screen with machinery.
Open Light mode →Expose the machinery
Select a Mancer and inspect orchestras, agents, runs, evidence, Archive and output boundaries. Anomancer is the editorial and publishing workspace.
Sign in to Workbench →Public / private
A glass wall is not an open door.
The architecture view can be public without turning private Lighthouse into a public control surface.
/en/core
- agent roles and contract structure
- built-in orchestras
- evidence and authority boundaries
- public model-route and tool-surface structure
- demo receipts and release provenance
/lighthouse
- real runs and run history
- prompts, raw content and working memory
- workspaces and custom orchestras
- tool execution and approvals
- server settings, model targets and secrets
ROADMAP · CURRENT 1.24.0Open the Anomancer development map
Current state and direction
Lighthouse gathers the work worlds into one environment.
1.24.0 shifts the priority from adding isolated views to building one application shell. First the two Lighthouse modes and the Anomancer workspace migration become clear; new Mancers then grow on top of that structure.
Lighthouse convergence
One private entry point
/lighthouse is canonical. /admin and /lahetyskone remain compatibility routes, not user-facing product names.
Light mode + Workbench
Conversation and deep work share one session and one Core. Users change depth without changing mental models.
Anomancer becomes native
The existing editorial application is decomposed into Lighthouse modules. Publishing is separated from editorial work through Publishing Target adapters.
From workbench to a verified release path
Codemancer + safe operations
The workbench, tests, diffs and plan-hash-bound human approval gates became one governed path.
Senior audit closure
The evidence truth model, accessibility matrix, release receipt and live-path verification moved into the release gate.
Public UI/UX polish
Dispatches, progressive evidence disclosure, Core typography, the Admin route and the Codemancer opening path were polished.
New work worlds
Auditomancer
Software, agent, UI/UX, accessibility, security, evidence and semantic audits. First loop: Auditomancer → Codemancer → Nanomancer → human.
Datamancer
Research question, hypotheses, dataset, methods, analysis, result, uncertainty and report. Result and interpretation remain separate objects.
Stylemancer
Design system, typography, layout, assets, UI, CSS and visual regression as one artifact chain.
Teachmancer
Goals, prerequisites, curriculum, exercises, assessment, feedback and progress from approved technical material.
Ecomancer
Market, finance and risk analysis as observation → assumption → scenario → risk → counter-scenario → decision proposal → human.
Cybomancer
Authorized security and adversarial testing only for owned, explicitly permitted, sandbox or CTF targets. No scope, no run.
Orchestration, memory, models and tools
Orchestra Registry V2
A stage may be an agent, plugin, tool, archive query, model, checkpoint, human approval or output adapter.
Context Gateway
Task → workspace policy → orchestra policy → Archive → selected memory → model. Context Inspector shows what a run may read before it starts.
Archive Graph
Project, Decision, Artifact, Run, Source, Audit and Dataset objects gain relations such as DERIVED_FROM, VALIDATED_BY and CONTRADICTS.
Multi-model Runtime
Multiple model families, per-stage routing, cost and token budgets, allowlists, health, timeout, fallback and model receipts.
Tool Sandbox
Capability Permission → Tool Broker → Sandbox → Receipt → Human approval. Tool authority never becomes an unrestricted shell.
Self-hosted Development Loop
Anomancer source → Codemancer → change proposal → tests → Nanomancer → Auditomancer → human review → apply. Governed, not autonomous.
The system starts observing itself
Cross-Mancer Workflows
Mancers exchange approved artifacts through Archive, Grant and Context Gateway without direct access to each other's internal state.
Command Palette / Core Search
Ctrl/Cmd + K opens workspaces, projects, runs, Archive, orchestras and settings from one global command surface.
Observability
Runs, latency, cost, models, errors, retries, tool calls, archive reads, context size, approval waits and regressions become visible.
Policy / Constitution Inspector
Before a run, users can inspect capabilities, denied actions, approval gates, Archive permissions and tool permissions.
Backup / Export / Restore
Projects, artifacts, Archive, receipts, constitutions, Mancer packages and settings export to JSON/Markdown/ZIP and return through validation and preview.
Lighthouse Constitution · Phase 8
The shared Lighthouse structure passes its final conformance gate: UI layers, boundaries, QA contracts and pre-release verification are checked as one coherent system.
Personal stress testing first, multi-user only later
Personal Hardening
Long-term use, real projects and audits, multiple model families, thousands of orchestra stages, Archive growth, backup/restore, cost calibration, permission boundaries and sandbox tests.
Optional Multi-user Core
Only after the personal Core proves itself: tenant isolation, organizations, roles, secret vault, key and budget isolation, rate limits, abuse prevention, audit log, retention, deletion, export, billing and privacy.
