Current state · 14 Aug 2026

Architecture & delivery webdoc

One governed control plane.
No hidden path around it.

Conduit coordinates repository knowledge, deterministic security, test generation, documentation, and developer-AI governance—locally, through explicit policy and evidence.

22decision artifactsin the Phase −1 review packet
14blocking decisionsall currently open
12required sign-offsnamed approvals pending
0runtime servicesimplementation intentionally frozen
01 / TECHNICAL INFOGRAPHIC

Architecture built around
enforced boundaries.

The approved baseline separates interaction, control, capabilities, knowledge, model, evidence, and distribution. Every arrow is a contract; every missing arrow is deliberate.

Interactive system map

Select a plane to inspect its contract and boundary.

DENYdirect model accesshost model portcontent telemetryremote fallback
02 / DELIVERY SEQUENCE

Ten gates from threat model
to operating model.

Security, identity, evidence, and output handling are prerequisites—not cleanup work. Each phase starts only when the preceding exit evidence is accepted.

−1
CURRENT · FROZEN

Approval & threat model

PHASE −1

Approve boundaries before any runtime implementation advances.

Key outputs
  • Threat model, data flows, abuse cases, and failure matrix
  • Seven architecture decisions and reconciled product backbone
  • Named ownership, provisioning, model/legal, and incident records
Exit evidence

14 blocking decisions closed; 12 named sign-offs recorded; high and critical findings closed or accepted.

0
NEXT · GATED

Contracts & adversarial harness

PHASE 0

Freeze one coherent v2 contract family before runtime code.

Key outputs
  • Capability, workflow, IPC, evidence, context, policy, and model contracts
  • Golden fixtures shared by TypeScript and Python SDKs
  • Tamper, downgrade, replay, cancellation, size, and content-leak tests
Exit evidence

Owners approve semantics and classification; adversarial suites pass; no runtime listener or model client ships early.

1
PLANNED

Sealed model plane

PHASE 1

Prove the single local inference boundary on workstation and build agent.

Key outputs
  • Restricted conduitd identity and authenticated OS IPC
  • Digest-pinned model runtime without a host-published API
  • Gateway redaction, limits, cancellation, health, and output validation
Exit evidence

Gateway-off and standard-user bypass tests fail closed; packet capture proves zero model-plane egress.

2
PLANNED

Evidence plane

PHASE 2

Make every governed operation auditable without exporting content.

Key outputs
  • Closed-schema evidence SDKs and bounded local queue
  • Signed or hash-chained export batches
  • Protected append-only collector tier and failure semantics
Exit evidence

Synthetic secrets, paths, prompts, code, outputs, and exceptions cannot cross the metadata boundary.

3
PLANNED

TestGen vertical slice

PHASE 3

Deliver one narrow end-to-end workflow before broad integration.

Key outputs
  • Isolated worktree and signed validator command templates
  • Scoped inference:testgen request through the gateway
  • Parse, containment, dependency, secret, size, test, and human gates
Exit evidence

Generated tests remain proposals; no repository write or PR occurs without deterministic gates and approval.

4
PLANNED

Remaining adapters

PHASE 4

Onboard the other specialist capabilities without weakening their independence.

Key outputs
  • RepoScribe commit-bound structured knowledge adapter
  • Argus deterministic security adapter
  • Copilot Governance policy-domain adapter
Exit evidence

All adapters pass behavioral, permission, bypass, and gateway-off contracts while retaining independent deterministic behavior.

5
PLANNED

Policy lifecycle & signing

PHASE 5

Operate immutable policy and artifact promotion with safe rollback.

Key outputs
  • Signed registry lifecycle, expiry, revocation, and last-known-good rules
  • Domain evaluators behind one policy envelope
  • Signer separation and downgrade protection
Exit evidence

Tampered, expired, unknown-signer, and downgraded artifacts are rejected consistently.

6
PLANNED

CLI, ADO & IDE

PHASE 6

Expose proven workflows through developer and pipeline surfaces.

Key outputs
  • Production CLI and self-hosted Azure DevOps task
  • IDE host after CLI semantics stabilize
  • Approval, cancellation, reason, and artifact experiences
Exit evidence

Surfaces are thin clients of the same authenticated contracts; no alternate model, policy, or evidence path exists.

7
PLANNED

Console & documentation

PHASE 7

Add the metadata-only governance experience after behavior is stable.

Key outputs
  • Operational documentation and support playbooks
  • Metadata-only governance console
  • Adoption, evidence health, policy, and version views
Exit evidence

Console data paths contain no source-derived content and use production semantics rather than placeholders.

8
PLANNED

Controlled pilot

PHASE 8

Exercise the system with bounded repositories, users, and rollback authority.

Key outputs
  • Named pilot cohort and repository allowlist
  • Capacity, support, privacy, and incident drills
  • Measured quality, latency, adoption, and false-positive evidence
Exit evidence

Pilot risks are resolved or accepted; operational owners approve a production decision.

9
PLANNED

Production operating model

PHASE 9

Run Conduit as a governed bank platform with durable accountability.

Key outputs
  • SLOs, capacity, vulnerability, model, and policy operations
  • Change, incident, recovery, and evidence-retention procedures
  • Ongoing evaluation and capability certification
Exit evidence

Service ownership, controls, evidence, recovery, and continuous review operate under approved production policy.

03 / CURRENT GATE

Architecture defined.
Runtime intentionally absent.

The repository contains useful pre-revision v1 prototypes. Green tests prove those prototype contracts are internally consistent; they do not approve deployment or unlock Phase 1.

Established

Reviewable architecture baseline

  • Strict TypeScript monorepo and tested v1 prototype schemas
  • Threat model, five data flows, failure matrix, and abuse cases
  • Seven ADRs covering isolation, evidence, workflow, Git, and providers
  • Revised v2 contract inventory and deterministic workflow model
!Blocking now

Ownership and proof

  • Name reviewers, platform owners, capability owners, and deputies
  • Prove private GPU model transport and zero model-plane egress
  • Open ADO, collector, append-only evidence, KMS, and signing records
  • Approve exact model, LoRA, licence, and training-data provenance
Not built

No production runtime yet

  • No conduitd daemon or authenticated IPC implementation
  • No sealed model plane, gateway, or capability adapters
  • No central evidence collector or signed distribution service
  • No CLI, ADO task, IDE host, or governance console
The next executable move

Close Phase −1 with named evidence.

Record every reviewer, decision, UTC timestamp, reviewed commit, and change or ticket. Then—and only then—revise the v2 contracts and adversarial harness in Phase 0.

Open approval record
04 / NON-NEGOTIABLES

The architecture’s
six load-bearing rules.

These constraints are the backbone. A future interface may expand, but it cannot silently weaken the local content boundary, source of truth, policy authority, or evidence model.

01

Model is replaceable

Callers choose an approved purpose—not a provider, endpoint, hostname, or mutable tag.

02

Capabilities are pluggable

Signed manifests declare operations, schemas, scopes, permissions, sandboxes, validators, owners, and expiry.

03

Git is authoritative

Repository knowledge is local, derived, commit-bound, and never becomes a competing source of truth.

04

Policy is enforceable

The deterministic control plane authorizes actions; model output is always untrusted input.

05

Evidence carries no content

Paths, prompts, code, outputs, arguments, exceptions, and generic catch-all attributes are forbidden.

06

Local inference stays local

The model plane has no host-published port, no egress, no download path, and no silent remote fallback.