Trust Posture
Replay determinism and evidence coverage from the live runtime.
0.0% replay determinism · 0.0% evidence coverage
What bp Sphere guarantees, and how the live implementation aligns to enterprise governance
bp Sphere is a deterministic, policy-bound Decision Operating System operating alongside BP systems of record.
Operating mode: LIVE · Domains visible: 10 · Entities tracked: 0.
Architecture, governance, context, trust, and learning capabilities across the live bp Sphere system.
Replay determinism and evidence coverage from the live runtime.
0.0% replay determinism · 0.0% evidence coverage
Semantic and memory-backed context available to decisions.
0 graph-backed decisions · 0 memory-assisted decisions
Mission and workflow orchestration running through the transaction spine.
0 workflow instances · 0 objects under spine
Shared platform deployed through tenant and domain overlays.
10 canonical domain packs · 114 SOR adapters
Measured release posture from replay and evidence health.
BLOCKED · 0.0/100
| Capability | Status | Runtime proof | Surface / endpoint |
|---|---|---|---|
| Experience Orchestration Layer | Surface available | Shared decision objects render across desktop, mobile, and chat surfaces. | /ui/mission/p2p, /ui/mobile-cockpit, /ui/enterprise-chat |
| Governed Chat Interface | Surface available | Chat resolves role, mission, case, evidence, policy, action contract, replay, and feedback. | /ui/enterprise-chat |
| Workforce Intelligence Integration Fabric | Surface available | Assistant registry, connector packages, certification, compliance mappings, identity resolution, failover drills, and workforce coordination APIs. | /ui/workforce-intelligence-fabric, /ui/assistant-operations-center |
| Token Economy Control Plane | Surface available | LLM calls are routed, cached, denied, downgraded, or escalated before spend occurs; token value is attributed to decisions. | /ui/ai-cost-usage, /api/iaf/decision-intelligence/token-economy/decision |
| Guardrail Policy Engine | Surface available | Policy evaluation fails closed in production posture; non-fail-closed failures route to escalation instead of silent execution. | /ui/policy-registry, /ui/control-plane |
| Decision Replay + LLM Determinism | Surface available | Execution seed, prompt/context hash, evidence hash, policy version, and replay records are persisted and validated. | /ui/decision-journey, /ui/single-decision-audit, /ui/decision-replay-studio |
| Externally Verifiable Evidence | Surface available | Evidence bundles are signed with asymmetric verification and can be checked through the verify endpoint. | /ui/evidence, /api/iaf/decision-intelligence/evidence/verify |
| Runtime Adoption Audit | Endpoint available | Agents/workflows are audited for identity, policy, evidence, replay, value, token, and learning seam adoption. | /api/iaf/decision-intelligence/runtime-adoption-audit |
| Skill-Binding Learning Promotion | Endpoint available | Skill learning overlays require evidence, confidence, and runtime effect before promotion into runtime metadata. | /api/iaf/decision-intelligence/skill-learning-overlays/{id}/validate |
| Autonomy Demotion Enforcement | Endpoint available | Telemetry demotion guidance writes supervisory state, event logs, and owner review queue items. | /api/iaf/decision-intelligence/autonomy/demotions/enforce |
| Shared Case-State Propagation | Endpoint available | One case resolution updates analyst state, supervisor state, value records, replay reference, and CFO rollup readiness. | /api/iaf/decision-intelligence/case-state/{case_id}/rollup |
| Observability Readiness | Endpoint available, env-bound | Production telemetry posture exposes OTEL endpoint status, Prometheus/failure-mode surfaces, and SLO targets. | /api/iaf/decision-intelligence/observability/readiness |
Reusable runtime capabilities: event ingestion, context graph, agent orchestration, policy gates, evidence vault, replay, learning, observability, and action routing. These are tenant-neutral and should not carry bp-specific process assumptions.
Boundary: platform owns runtime primitives, control contracts, schemas, telemetry, and reusable services.
bp-specific configuration: source-system endpoints, mission packs, policies, approval matrices, glossary terms, evidence mappings, role models, SOR access rules, and validation datasets.
Boundary: bp overlay owns business semantics, policies, data access, evidence sources, and operational ownership.
Business context is reconstructed through ontology, enterprise signals, historical state, policy context, and CREST bundles.
Live surfaces: Enterprise Intelligence Fabric · CREST Context Studio
Decision memory, knowledge registries, GraphRAG, and learning fabric convert institutional knowledge into reusable operating logic.
Live surfaces: Decision Memory · Learning Fabric
Value is linked to decisions through recorded impact, protected value, attribution confidence, and double-counting controls.
Live surfaces: Value Attribution · Decision Ledger
Every governed decision can carry evidence hashes, lineage, replay support, and policy/version provenance.
Live surfaces: Evidence Vault · Decision Replay Studio
Skills, missions, triggers, and bounded autonomy are composed into reusable enterprise execution flows.
Live surfaces: Skill Fabric · Runtime Overview
Human authority, thresholds, queues, inline policy context, and supervisory control remain part of the runtime contract. Policy now sits as a hard gate between the lifecycle and autonomy gates in the supervisory chain.
Live surfaces: Policy Library · Decision Records · Policy Studio
Twelve certification categories — ontology execution, policy governance, evidence integrity, agentic fabric, replay determinism, supervisor governance, external signal intelligence, simulation runtime, value attribution, AI adoption, institutional learning, infrastructure resilience — each backed by runtime paths and tests. Production releases for bp pass through an explicit ERCS gate before publish; the UI must show measured score and failed controls rather than imply universal Platinum status.
Current measured gate: BLOCKED · score 0.0/100 · replay 0.0% · evidence 0.0%
Example. A finance pack passes 11 of 12 categories but fails the simulation-fidelity test (forecast drift > tolerance). The ERCS release gate blocks promotion, the failing category posts to the certification inbox, and operators see the exact assertion that failed — not a generic "deploy blocked". Illustrative — categories and thresholds are configurable per release.
Live surfaces: ERCS Scorecard · ERCS Proof Suite · Certification Inbox
External signal fabric ingests commodity (Brent / WTI / gas), FX, logistics, weather, geopolitical, regulatory and supplier-risk feeds. A correlation engine walks ontology relationships to surface cross-domain impact, drives forecast drift detection, and generates governance-grounded strategic recommendations with confidence scoring.
Example. An external signal (e.g. Brent crude) is ingested as bpsphere.strategic.signal_ingested. The correlation engine resolves cross-domain impact through ontology relationships (treasury, capex, downstream, procurement, forecast drift) and emits bpsphere.strategic.impact_detected followed by bpsphere.strategic.recommendation_generated. Affected missions are surfaced on the executive copilot with citations to decision_id, policy_version, and evidence_hash. Illustrative — signal source, agent count, and timing vary by tenant and live data state.
Live surfaces: Strategic Intelligence · Executive Copilot
Enterprise digital twin engine with scenario branching, counterfactual replay over the existing replay tape, policy simulation against historical decisions, and stress-test fixtures (CFO liquidity, supply-chain Gulf delay, payment-hold threshold). Simulation runs anchor back to original decision IDs so value attribution survives replay.
Example. "What if Brent −12%, DSO +7d, FX −4% next quarter?" The scenario engine projects cash flow, working capital, covenant exposure, treasury pressure and margin compression along three branches. A separate counterfactual replays a prior period’s payment-hold decisions under an alternate threshold and quantifies the risk delta — without touching production state. Illustrative — signal mix, branch count, and threshold values are configurable.
Live surfaces: Simulation Runtime · Replay Theater
Pgvector-backed memory graph with similar-case retrieval. Learning proposals are bounded edits (prioritization weights, escalation thresholds, confidence calibration only — never rules or ontology) and pass through a replay-reproducibility gate plus Trust-fabric attestation before any apply. Review, apply and rollback permissions are split four-eye.
Example. A supervisor consistently overrides low-confidence invoice holds (all released as safe). The system proposes raising the auto-release confidence threshold — a bounded prioritization edit. The replay-reproducibility test confirms the original decisions still verify under the proposed threshold. Reviewer (learning.evolution_review) approves; a different role (learning.apply) applies. Policy rules unchanged, ontology unchanged, the original signed bundle still verifies. Illustrative — thresholds and counts vary by feedback volume.
Live surfaces: Learning Proposals · Institutional Memory
Every dashboard KPI traces UI → SOR query → GL posting → vendor / entity reference → freshness SLA, with partial-coverage disclosure when an upstream is unavailable. Closes the "show me the evidence" question at the CFO axis.
Example. A DSO drill-down opens its live lineage: iaf_customer_invoices rows aggregated by aging bucket, evidence-coverage percentage shown, vendor and customer references resolved against iaf_customers and iaf_vendors. When an upstream SOR is unreachable, the lineage row marks data_source_type=UNAVAILABLE and the KPI value carries a partial-coverage disclosure. The same path is implemented for DPO and CCC. Illustrative — specific values vary by tenant and live data state.
Live surfaces: Decision Trace · Value Attribution · Adoption Intelligence
NATS JetStream durable subjects across bpsphere.signal.*, bpsphere.strategic.*, bpsphere.simulation.*, bpsphere.learning.*. EventDispatcher with idempotency ledger and dead-letter queue. AutoRollbackWorker subscribes to bpsphere.regression.detected and reverses a published pack when z-score breaches threshold. Guardian and Trust fabrics subscribe to supervisory events on bpsphere.>.
Example. A bad pack publish drives p99 latency on a finance mission past its rolling-window threshold. Observability detects the z-score breach, emits bpsphere.regression.detected, AutoRollbackWorker rewinds to the prior signed pack and emits bpsphere.governance.rollback_executed with the rationale plus before/after metrics on the audit log. Duplicate deliveries are absorbed by the idempotency ledger. Illustrative — latency and z-score thresholds are configured per mission; rollback timing depends on stream lag.
Live surfaces: Runtime Observability · Mission Pack Manager · Operator Workflow
Forward + backward recovery for cross-SOR transactions. Steps declare compensations; on failure the engine plays compensations in reverse with bounded retries. Step dependencies, retry policy, and persistent state are all first-class. Used internally by mission orchestration; available to tenant pack authors via the SDK.
Example. A four-step payment workflow reserves a budget, posts a journal entry, notifies the vendor, and updates the AP ledger. If the vendor notification fails, the saga compensates by reversing the journal entry and releasing the budget. The original transaction never partially commits. Illustrative — step shape and compensation policy are configurable per workflow.
Live surfaces: shared_capabilities/workflows/saga.py · Composition Studio
Every cross-SOR action passes through an idempotency registry keyed by transaction id + request hash. Replays, duplicate webhooks, and retried API calls deduplicate cleanly. Paired with the EventDispatcher’s ledger-backed idempotency, the platform absorbs at-least-once delivery without double-actioning the upstream SOR.
Example. A network partition retries the same NATS-delivered "post invoice" message three times. The transaction spine recognises the identical idempotency key on the second and third deliveries and replies with the original action result — SAP receives exactly one journal posting. Illustrative — key shape and retention window are configurable per SOR.
Live surfaces: shared_capabilities/transaction_spine/idempotency.py
Five routing strategies (primary-fallback, cost-optimised, latency-optimised, round-robin, quality-threshold) across nine providers (Anthropic, OpenAI, Groq, Cohere, Ollama, NVIDIA, Mistral, Grok, vLLM). Per-request max_cost budgets, prompt versioning with DRAFT/ACTIVE/ARCHIVED lifecycle and built-in A/B testing.
Example. A cost-optimised routing strategy sends a routine vendor-classification prompt to the cheapest available model that meets the configured quality threshold; an SLA-critical CFO summarisation prompt is force-routed to a flagship model under the latency-optimised policy. Prompt A/B variants are picked deterministically per decision_id so replay is reproducible. Illustrative — routing policy and quality thresholds are configurable per tenant.
Live surfaces: shared_capabilities/ai/llm/gateway.py · shared_capabilities/ai/prompts/manager.py
OpenTelemetry auto-instrumentation for FastAPI / SQLAlchemy / psycopg2 / HTTPx is on by default. Canonical platform SLOs (availability 99.9%, p95 latency, error rate) are recorded against every /api/platform/* request and surfaced at /api/platform/slo. A sliding-window rate limiter shapes per-tenant / per-API-key traffic. Data-residency policy is enforced as HTTP 451 on cross-border violations when a tenant declares a region allow-list.
Example. A tenant configured with allowed_regions: [EU, UK] in tenant_metadata.yaml receives a 451 from /api/platform/* when the ingress geo-IP resolves the request to US; the violation is audit-logged with the tenant, framework rule, and source region. Operator can run the same policy in log_only mode first to stage rollout. Illustrative — region allow/deny lists and enforcement mode are configurable per tenant.
Live surfaces: /api/platform/slo · shared_capabilities/observability/ · shared_capabilities/security/http.py · shared_capabilities/trust/compliance/residency.py
Dedicated databricks_sor.event_ingest.DatabricksEventIngestor subscribes to bpsphere.decision.logged, bpsphere.agent.*.evidence.committed, bpsphere.policy.attestation.created, bpsphere.gate.decision and writes through to the databricks_event_lineage Delta table — closing the streaming Postgres → Lakehouse gap for bp analytics.
Example. A duplicate-payment agent decides to hold an invoice. The decision streams into databricks_event_lineage carrying the original decision_id, the gate verdict, the evidence_hash, and the attached value attribution — queryable from the bp analytics workbench alongside historical decisions in the same Delta table. Illustrative — latency and retention horizon depend on stream load and Lakehouse retention policy.
Live surfaces: Tenant Overlay Manager · Observability
Mission- and tenant-scope kill switches with 4-hour gate-escalation SLA and 1-hour kill-switch review SLA. Operator playbooks (e.g. pack promotion checklist) run synchronously with bounded steps and survive mid-chain agent failure with context inheritance and evidence sealing intact.
Example. During an SOR brownout, an operator pauses a mission with a one-click action via the supervisory control surface. No new agents activate, in-flight escalations stay visible in the supervisor queue, replay history stays sealed, and existing escalation SLAs continue ticking. When the SOR recovers the operator resumes the mission and the queue drains naturally — no decisions silently rerun. Illustrative — SLA values are configurable in the supervisory policy pack.
Live surfaces: Operator Workflow · Certification Inbox · Composition Studio
Runtime Overview · Decision Memory · Enterprise Intelligence Fabric · Technology → Runtime Mapping · Value Attribution · CREST
Platform-tier surfaces: Platform Home · ERCS Scorecard · ERCS Proof Suite · Strategic Intelligence · Simulation · Executive Copilot · Learning Proposals · Institutional Memory · Composition Studio · Observability · Replay Theater · Certification · Tenant Overlay · Policy Studio · Ontology Studio · Pack Manager · Operator Workflow · Value Attribution · Decision Trace · Adoption Intelligence
Semantic spine, business objects, runtime context bundles, and cross-domain references that normalize meaning before execution.
Why it matters: Makes decisions context-aware and tenant-consistent instead of prompt-only or system-local.
Context reconstruction layer connecting enterprise signals, institutional memory, policy context, and decision-ready state.
Why it matters: Lets agents and humans work from reconstructed enterprise context, not fragmented application screens.
Decision memory, knowledge registries, GraphRAG, and learning fabric that preserve institutional knowledge beyond individuals.
Why it matters: Turns prior decisions and domain knowledge into reusable operating intelligence.
Decision-linked financial impact, protected value, effort avoided, and attribution confidence with double-counting controls.
Why it matters: Connects automation and governed judgment to cash, cost, risk, and working-capital outcomes.
Evidence vault, deterministic replay, lineage, integrity hashes, and replay-readiness checks across runtime decisions.
Why it matters: Provides proof that decisions are reproducible, governable, and audit-ready.
Skill composition, mission orchestration, event-driven triggers, and bounded autonomy across agents and roles.
Why it matters: Moves from isolated assistants to governed enterprise execution.
Role-aware authority thresholds, supervisory control, HITL queues, inline policy context, and fail-closed decision gating.
Why it matters: Keeps humans in control at the right boundary while still scaling automation.
NATS/event routing, SOR adapters, workflow instances, and mission triggers running beside enterprise systems of record.
Why it matters: Lets bp Sphere operate as a decision sidecar rather than an ERP replacement.
Every count and identifier below is bp tenant specific. Platform capabilities described elsewhere (148-pod SOR fabric, 9-provider LLM gateway, EIF, FIL, Context Studio) are available to bp; this page shows what bp tenant currently exercises.
bp tenant currently served at https://prod.sphere-iris.com via Cloudflare worker (quick tunnel → in-cluster ingress → bp Sphere shell → bp Sphere dev service). Other tenants on the same fabric have their own worker URLs and are not represented in this tech pack.
The bp tenant now exposes an architect-run command-line path: bp-now, bp-close-now, bp-financial-position, bp-digital-twin, bp-close-runtime, bp-runtime, bp-provenance. Every headline runtime number must disclose provenance badges: ● live query · ◐ seeded baseline · ◇ estimate/model · ◆ deterministic replay/policy. This is intentionally self-disclosing: the runtime query is live, workshop baselines are BP-shaped seeded data, and production SOR connectivity remains fail-closed until BP credentials and feeds are supplied.
Continuous Close is now documented as a finance digital twin, not a close dashboard. The hero proof asks: If BP closed the books right now, what would the financial statements look like? The runtime assembles actuals, forecast accruals, forecast provisions, reconciliations, controls, evidence, confidence, open exceptions, and replay into a current financial position.
9 providers are wired at the platform level (Anthropic, OpenAI, Gemini, Cohere, Grok, Groq, NVIDIA, Ollama, vLLM). bp tenant runs OpenAI via environment-configured model in production today; the gateway will route to a fallback provider on request, gated by eval_harness response-quality scoring before display.
bp tenant bp Sphere runtime
│
│ LiveSORClient (HTTP / async)
│ same code path used at tenant activation
↓
┌────────────┬───┴──────┬──────────┬──────────┐
↓ ↓ ↓ ↓ ↓
FINANCE PROCUREMENT RISK MARKET DATA
─────── ─────────── ────── ─────── ─────
sor-treasury sor-ariba sor-cyber-risk sor-databricks
sor-coupa sor-ai-gov-trust
sor-audit-controls-fabric
FEEDS
─────
sor-commodity-price-feed
sor-fx-rate-feed
sor-macro-indicator-feed
OPERATIONS
──────────
sor-servicenow
Each SOR runs as its own production-shape FastAPI service in the same cluster (its own port, its own database, its own validation logic). bp Sphere calls them over real HTTP through LiveSORClient — the same code that will call bp's actual SAP, Ariba, ServiceNow, and Treasury endpoints at tenant activation. Only the DNS target inside each adapter changes.
# iris_runtime/src/iris_sor/services/sor_client.py (simplified)
async with LiveSORClient(target="sor-ariba") as client:
suppliers = await client.get(
path="/api/v1/suppliers",
params={"realm_id": "bp", "active": True},
)
if not suppliers:
raise SorDataError("ariba supplier set empty for bp realm")
# At tenant activation, the only change:
# sor-ariba.platform-services.svc.cluster.local
# → bp.ariba.cloud (or whatever bp's actual Ariba endpoint is)
# Code path, evidence pack assembly, FIL sealing are unchanged.The service registry currently exposes 114 registered SOR endpoints covering finance, procurement, treasury, trading, tax, HR, risk, planning, market data, reporting, and operational systems. The table above is the critical BP workshop subset because those services directly support the current mission demos: governance, procurement, controls, market signals, cyber risk, Databricks, FX, macro, ServiceNow, and treasury. Additional endpoints such as SAP S/4HANA, SAP GRC, Workday, BlackLine, Bloomberg, Endur, Murex, Kyriba, Salesforce, ServiceNow GRC, Avalara, Vertex, OneStream, Snowflake, and Power BI are already present in the registry and can be bound into bp workflows through configuration.
service_ports.json, which currently registers 114 SOR endpoints. That registry includes the wider enterprise service landscape and is what the runtime uses for adapter discovery and endpoint resolution.credit_intelligence) declares which SORs are required for evidence assembly. The agent runtime resolves the SOR list, makes the calls in parallel, and gates the pack on evidence completeness before passing to the policy layer.SorDataError is raised, the partial pack is sealed by FIL with a degraded-mode marker, and the decision either falls back to a cohort precedent or escalates to HITL. Recovery is observable in the FIL revision audit.
Platform shared pack (registry)
────────────────────────────────
finance-context-pack
▲
│ parent_pack_id
│
┌─────────┴────────────────────┐
↓ ↓
bp-upstream-ap-pack bp-trading-credit-pack
(tenant_extension) (tenant_extension)
beta · 87% coverage beta · 84% coverage
Adds: Adds:
Objects: Objects:
Contract Counterparty
Milestone Exposure
AFE MarketSignal
Waiver
Decisions:
Decisions: dynamic_credit_limit_review
contract_milestone_ proactive_credit_renewal_
invoice_validation intervention
maintenance_consumption_
service_verification Policies:
BP.CREDIT.LIMIT_THRESHOLD
Policies: BP.CREDIT.EARLY_WARNING
BP.P2P.CONTRACT_VARIANCE
BP.P2P.MILESTONE_BILLING
# platform/registries/context_marketplace.yaml
packs:
- pack_id: bp-upstream-ap-pack
pack_type: tenant_extension
parent_pack_id: finance-context-pack
maturity: beta
coverage_pct: 0.87
includes:
objects: [Contract, Milestone, AFE, Waiver]
decisions:
- contract_milestone_invoice_validation
- maintenance_consumption_service_verification
policies:
- BP.P2P.CONTRACT_VARIANCE
- BP.P2P.MILESTONE_BILLING
references:
- tenant_extensions/bp/upstream_ap/context_pack.yaml
- pack_id: bp-trading-credit-pack
pack_type: tenant_extension
parent_pack_id: finance-context-pack
maturity: beta
coverage_pct: 0.84
includes:
objects: [Counterparty, Exposure, MarketSignal]
decisions:
- dynamic_credit_limit_review
- proactive_credit_renewal_intervention
policies:
- BP.CREDIT.LIMIT_THRESHOLD
- BP.CREDIT.EARLY_WARNING
references:
- tenant_extensions/bp/trading_credit/context_pack.yamlbp tenant uses a measured 13-domain Tenant Certification rubric across context, evidence, policy, replay, agent runtime, security, and operations. The publish-blocker gate prevents merging code that drops any domain below threshold, and the certification surface should show the current score and failing controls rather than a static perfect-status claim.
tenant_extensions/bp/{name} with a parent_pack_id referencing the shared platform pack. The new pack inherits all parent objects, decisions, and policies, and adds bp-specific extensions on top./context/ops/scorecard endpoint computes coverage and confidence per pack on every refresh; drift below target triggers a workqueue item for the bp stewards listed above.bp Sphere operates as the governed finance decision, control, evidence, and accountability runtime inside bp guardrails. bp Sphere is presented as the decision and control runtime inside tenant guardrails, not as a competing data or AI platform.
OneData and UDP govern trusted data. Nexus and LaunchPad govern AI assets. Identity governs access. bp Sphere turns those governed data products, policies, controls, events, and human accountabilities into explainable finance decisions, actions, evidence, replay, and transformation outcomes.
Distributed intelligence control plane — architecture, topology, and governance model
bp Sphere (bp Sphere runtime) is a distributed, policy-bound intelligence runtime with a dedicated Enterprise Control Plane deployed alongside bp systems of record.
It is not an ERP replacement. It is not a data warehouse. It is not a chatbot wrapper.
It is a governed orchestration layer that:
Every decision is deterministic. Every agent is policy-registered. Every execution is replayable.
Scenario:
Supplier invoice: $12.4M
Status: Blocked (price mismatch)
bp Sphere flow:
Signal:
- SAP CFIN emits invoice_blocked
Context:
- Supplier has 3 prior disputes
- Contract variance threshold: 2.0%
- Current variance: 3.8%
Decision:
- Materiality > $500K so dual approval required
- Simulate release risk vs hold risk
Recommendation:
- Hold invoice
- Escalate to P2P lead
Evidence:
- inputs_hash seals supplier, contract, and invoice snapshot
- outputs_hash seals recommendation and simulation outputs
- policy_reference: p2p_policy.yaml#variance_rule
Outcome:
- Decision logged and replayableGoverned narration · Deterministic click orchestration · Evidence-first credibility
The Conversational Command Layer (CCL) is not a chatbot wrapper and not a pre-recorded demo.
It is a governed orchestration and narration layer that:
CCL exists to solve a credibility problem: “Show me this is live, governed, and real.” CCL answers with inline proof.
Instead of saying: "We have a copilot."
bp Sphere's Conversational Command Layer is a governed narration and deterministic click-orchestration system that turns live runtime state into role-adaptive explanation — with every claim bound to policy, evidence hashes, replay IDs, and source provenance visible inline.
4-layer object model · Trigger engine · Cross-domain bridges · Tenant packs
The bp Sphere ontology provides a 4-layer semantic object model that defines how business entities are structured, related, triggered, and audited across the platform.
Unlike static data schemas, the ontology is active — it drives agent bindings, trigger rules, and cross-domain bridges.
Neo4j graph store · GraphRAG · Inference · Chain-of-thought
bp Sphere maintains a Neo4j-backed knowledge graph for contextual reasoning, combining entity relationships, semantic search, and multi-hop inference.
Evidence Intelligence Fabric (EIF)
─────────────────────────────────
Shared platform service
│
┌──────────┬────────────┼────────────┬──────────┐
↓ ↓ ↓ ↓ ↓
Discovery Resolution Lineage Pack Viewer
Service Service Service Service Service
Cross-system Per-record
evidence lineage:
discovery source / time
confidence /
match_posture /
governing_status
│
↓
bp Tenant EIF Case Packs (6):
─────────────────────────────────
journal_entry → EIF-PACK-JE-*
contract_validation → EIF-PACK-CONTRACT-*
credit_intelligence → per-decision
maintenance_verification → EIF-PACK-MAINT-4402
spend_intelligence → EIF-PACK-SPEND-0712
close_intelligence → EIF-PACK-CLOSE-0630
GET /context/coverage?domain=finance
→ HTTP 200
{
"coverage_contract": {
"id": "iris-context-coverage-v1",
"dimensions": [
"object_coverage", "relationship_coverage",
"event_coverage", "policy_coverage",
"decision_pattern_coverage", "evidence_lineage_coverage"
],
"weights": { "object_coverage": 0.20, ... },
"quality_gates": {
"minimum_confidence_pct": 0.75,
"minimum_freshness_sla_hours": {
"critical": 24, "high": 72, "standard": 168
}
}
},
"scorecard": [{
"domain": "finance",
"coverage_pct": 0.7219,
"target_pct": 0.90,
"trust_score": 0.725,
"governance": {
"current_state": "curated",
"next_state": "certified"
}
}]
}GET /context/graph/path?source_object=Supplier&target_object=Payment&domain=finance
→ HTTP 200
{
"domain": "finance",
"source_object": "Supplier",
"target_object": "Payment",
"path": ["Supplier", "Invoice", "Payment"],
"edges": [
{ "from": "Supplier", "to": "Invoice",
"reason": "Supplier context explains invoice demand, dispute, and fraud posture." },
{ "from": "Invoice", "to": "Payment",
"reason": "Invoice approval or hold changes payment execution timing." }
],
"path_confidence": 0.9
}Every EIF pack generated for a bp tenant decision is sealed by FIL: signed evidence hash, lineage row, and replay key. bp tenant currently holds ~22M signed revisions in iaf_agent_execution_revisions — every one of which can be replayed deterministically.
iris_runtime/src/iris_sor/services/evidence_intelligence_fabric.py and is invoked by every use case launch page. Context Studio runs as the separate context-graph deployment in platform-services (port 8080), backed by Neo4j and NATS.Deterministic execution · Policy gating · Evidence-coupled mission delivery
bp Sphere operates a single canonical execution contract across all 153 agents.
Registry version: 1.2.0 ·
Runtime agents: 153 registered, 153 implemented ·
LLM provider: shared_capabilities.llm.OpenAIClient ·
Operating mode: LIVE
Topology-aware orchestration · Capability routing · Task queue · HITL · Workflow engine
The bp Sphere Agent Mesh provides topology-aware orchestration for 153 agents, combining capability-based routing with a full automation platform for task queuing, HITL escalation, and multi-step workflow execution.
Governed delegation · SLA-enforced escalation · Evidence-bound approvals
Human-in-the-Loop (HITL) is not a fallback mechanism. It is a formal authority orchestration layer.
No execution may cross materiality boundaries without policy-defined authority.
Operating control centers · Deterministic enforcement · Role separation · Controlled autonomy promotion
The Enterprise Control Plane is the operating and governance layer above the operational data plane. Agents, signals, workflows, evidence retrieval, recommendations, and human approvals perform work; the Control Plane governs, pauses, recovers, audits, and tunes that work.
Positioning Statement (For Orals)
bp Sphere operates a centralized supervisory control plane that enforces registry validation, autonomy gating, policy evaluation, drift monitoring, and interruptible execution on every agent action — with deterministic replay and role-separated authority.
Deterministic rule evaluation · Version-controlled DSL · SOX-aligned enforcement
The Policy Engine is a separate, declarative governance layer that evaluates every agent decision before output. Agents propose. Policies decide.
No agent may emit a decision without policy evaluation.
Positioning Statement (For Orals)
bp Sphere operates a deterministic, version-controlled policy engine where agent logic is strictly separated from governance rules, materiality thresholds are tenant-defined, conflicts resolve to the most restrictive outcome, and every evaluation is replay-verifiable and SOX-auditable.
Reproducible by construction · Cryptographically sealed · Regulator-ready
Every bp Sphere decision is reproducible by design. Given the same input snapshot, the same policy version, the same model version, the same seed, and the same enterprise time — the system produces the same output, every time.
This guarantee is enforced at runtime, not assumed.
The Evidence Vault stores immutable decision artifacts with full lineage, cryptographic sealing, and audit export capability.
Positioning Statement (For Orals)
bp Sphere operates a cryptographically sealed, deterministic execution contract where every decision is replay-verifiable, counterfactual-testable, and retained for seven years under SOX-grade audit controls.
Canonical normalization · Cross-SOR identity graph · Traceable lineage
bp Sphere does not replicate ERP systems. It references systems of record as authoritative truth. The data architecture establishes:
The objective is not duplication — it is deterministic reasoning on normalized context.
Positioning Statement (For Orals)
bp Sphere operates a canonical context layer that harmonizes 114 systems of record into a version-aware, lineage-traceable entity model with cross-SOR identity resolution and domain-scoped access control — without replicating or mutating ERP truth.
Read-only intelligence · Event-driven ingestion · Failure-isolated architecture
bp Sphere integrates with 114 enterprise systems of record across bp's landscape. The integration principle is strict:
Observe → Normalize → Reason
Never mutate SOR truth.
All integrations are read-only by default. Guarded write-back is a controlled future capability requiring explicit governance activation.
Positioning Statement (For Orals)
bp Sphere operates a read-only, event-driven integration plane that normalizes 114 enterprise systems into versioned canonical snapshots, isolates SOR failures via circuit breakers, and guarantees deterministic reasoning without transactional coupling to SAP or Treasury.
Operational reliability · Decision quality assurance · Controlled evolution
bp Sphere observability operates across three independent but connected control loops:
Is the system available and performant?
Are agents producing correct, policy-compliant outcomes?
Has agent or data behavior shifted over time?
Observability is not passive logging. It is an active governance control surface.
Positioning Statement (For Orals)
bp Sphere operates under a measurable reliability and quality framework where execution health, decision integrity, and behavioral drift are continuously monitored, promotion is gated by shadow validation, and error budgets enforce disciplined evolution.
Zero trust enforcement · Defense in depth · Blast radius containment
bp Sphere operates under a strict zero-trust architecture. Every request is authenticated, authorized, domain-scoped, logged, and audited.
No implicit trust exists between:
Security is enforced at multiple independent layers.
Positioning Statement (For Orals)
bp Sphere operates a defense-in-depth, zero-trust architecture where identity, domain scope, policy enforcement, supervisory control, and immutable evidence collectively ensure that no unauthorized decision, data access, or privilege escalation can occur — even under breach assumptions.
Distributed control plane · Deterministic data plane · Event-driven orchestration · Production-grade DevSecOps
bp Sphere is deployed as a distributed, policy-governed, containerized control plane running on Kubernetes with:
This document specifies the full infrastructure substrate — from VPC networking to rollout governance.
Instead of saying: "We run on Kubernetes."
bp Sphere operates as a distributed, tenant-isolated control plane deployed on Kubernetes with deterministic replay guarantees, event-driven orchestration, immutable audit ledger, zero-trust middleware, and multi-layer CI/CD governance — engineered for enterprise-scale financial operations.
Progressive confidence model · Explicit risk gates · Governance-first rollout
bp Sphere deployment at bp follows a structured, three-phase rollout designed to:
No phase proceeds without satisfying exit criteria and formal checkpoint approval.
Instead of saying: "We have a 3-phase rollout."
bp Sphere follows a progressive confidence deployment model where integration, decision quality, governance maturity, and autonomy promotion are gated by explicit exit criteria, formal checkpoints, and executive sign-off — eliminating big-bang risk and ensuring audit-grade readiness at every stage.
The Enterprise Policy Intelligence Runtime is the policy decision point for Sphere. It converts enterprise rules, controls, approval thresholds, AI guardrails, data-sharing restrictions, model-routing constraints, authority limits, and evidence requirements into executable decisions that missions, agents, APIs, workflows, and user actions must respect.
The runtime prevents policy logic from fragmenting across UI components, API handlers, workflow scripts, and agent prompts. It centralizes policy evaluation so every important recommendation, action, data-sharing event, and write-back request is constrained by versioned, testable, observable, and auditable policy.
It does not replace source systems, identity providers, the evidence fabric, or the decision orchestrator. It governs those
layers by returning structured outcomes such as allow, deny, require_human_approval,
require_more_evidence, allow_recommend_only, allow_draft_only, and
allow_simulation_only.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_policy_intelligence_runtime.py and policy_as_code_runtime.py |
Certified by tests/test_enterprise_policy_intelligence_certification.py and policy single-source contract tests. |
| Policy API contract | GET /api/policy, POST /api/policy/evaluate, POST /api/policy/simulate, decision trace, override, compile, test, observability, and rollback contracts. |
Published from api/policy_as_code.py and surfaced in Policy Registry API documentation. |
| Decision ledger | Every material evaluation produces a policy decision identifier, reason codes, policy trace, evidence status, and ledger pointer. | Decision Runtime persists policy attestations and replay pointers for assurance packets. |
| Authority boundary | Agents and users are constrained to read, recommend, draft, approval-required, or execution-authorized modes. | Execution Gateway blocks business execution when policy proof is absent. |
| Evidence sufficiency | Policy evaluation checks required evidence before a recommendation or action can proceed. | Evidence Runtime and Enterprise Assurance Runtime consume policy decisions as current proof objects. |
| AI guardrails | Model use, external sharing, masking, tool access, human review, memory creation, and write-back are governed as policy decisions. | Enterprise agent runtime declares enterprise_policy_intelligence_runtime as a mandatory dependency. |
| Observability | Policy volume, latency, approval requirements, denials, overrides, missing evidence, and hot policies are tracked. | Operational surfaces: Policy Runtime, Policy Library, and Policy Studio. |
User / Agent / Mission / API / Workflow
|
v
Policy Evaluation Request
|
v
Enterprise Policy Intelligence Runtime
|
+-- Policy Registry
+-- Policy Compiler
+-- Policy Evaluation Engine
+-- Authority Engine
+-- Evidence Sufficiency Engine
+-- AI Guardrail Engine
+-- Data Sharing Policy Engine
+-- Execution Gate Engine
+-- Override and Exception Engine
+-- Policy Decision Ledger
+-- Policy Simulation Engine
+-- Policy Observability
|
v
Policy Decision Response
require_more_evidence.| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/policy | Discover active policy registry entries. | Read-only policy catalog. |
POST /api/policy/evaluate | Evaluate a user, agent, workflow, or API action against policy. | Authoritative policy decision point. |
POST /api/policy/simulate | Run non-mutating impact analysis for threshold, authority, or evidence-rule changes. | Simulation only; no production action. |
GET /api/policy/decisions/{decision_id} | Replay a policy decision with input facts, versions, reason codes, and output hash. | Audit and assurance trace. |
POST /api/policy/decisions/{decision_id}/override | Request or record controlled exception handling. | Human-approved, expiry-bound override path. |
GET /api/policy/observability | Expose latency, decision mix, denial rate, override rate, and missing-evidence metrics. | Operational readiness and control monitoring. |
Uses policy outcomes to determine whether a decision can be recommended, escalated, blocked, or executed.
Assembles evidence; policy determines whether that evidence is sufficient for the requested action.
Agents declare policy dependencies and must receive policy clearance before material tool use or business action.
Reconstructs the exact policy version, context, evidence references, actor, and outcome used at decision time.
A duplicate-payment risk case requests a hold recommendation and a possible payment release. The runtime evaluates duplicate payment controls, authority threshold, evidence sufficiency, AI output requirements, and write-back policy. The resulting policy decision allows the hold recommendation, blocks payment release, requires supervisor approval for high-value action, and writes a replayable ledger record with policy versions and evidence references.
{
"decision": "require_human_approval",
"recommendation_allowed": true,
"action_allowed": false,
"write_back_allowed": false,
"required_next_step": "supervisor_review",
"reason_codes": [
"duplicate_payment_risk_high",
"amount_above_threshold",
"write_back_requires_approval"
],
"evidence_status": "sufficient",
"ledger_pointer": "ledger://policy/{policy_decision_id}"
}
Prompts may reference policy summaries, and user interfaces may hide or disable blocked actions, but neither prompts nor UI state are the source of enforcement. Backend action APIs and execution gateways must validate the current policy decision before material action or write-back.
The Enterprise Decision Runtime is the core decisioning engine for Sphere. It converts signals, context, evidence, policy outcomes, agent recommendations, skill results, risk, value, and human authority into governed, explainable, auditable business decisions.
The Policy Runtime determines what is allowed. The Decision Runtime determines what should happen next within those constraints. It evaluates context, evidence, materiality, risk, value, authority, and agent output to produce a structured decision outcome and an operational next step.
It is not a source-system writer, raw workflow engine, or isolated agent. It is the governed orchestration layer that turns source-linked context and runtime intelligence into a decision record that can be explained, approved, executed through controlled channels, replayed, and measured.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_decision_runtime.py |
Defines runtime contract, layers, execution, live execution, replay, certification, audit package, policy simulation, and domain-pack contracts. |
| API surface | /api/iaf/enterprise-decision-runtime/* |
Includes contract, execute, execute-live, replay, replay-live, approval transition, registry, layers, certification, audit, and decision trace endpoints. |
| Live execution path | execute_decision_live() |
Persists DecisionLogRecord, EvidencePack, ReplayManifest, ReplayRun, ReplayStep, DecisionContractRecord, ToolInvocation, and RuntimePerformanceTelemetry. |
| Policy integration | Calls EnterprisePolicyIntelligenceRuntime.evaluate() before finalizing execution state. |
Live records include policy_decision_id, policy attestation hash, winning policy, and replay-visible policy boundary. |
| Skill integration | Routes selected skill execution through SkillFabricService.execute_skill() after policy and workflow planning. |
Tool invocations preserve skill ID, canonical skill ID, retries, SOR calls, token count, and evidence hash. |
| Human approval boundary | Creates DecisionContractRecord with approval status, required role, selected action, confidence, policies applied, and replay reference. |
Approval transitions are available through POST /api/iaf/enterprise-decision-runtime/approvals/{{decision_id}}/transition. |
| Replay and assurance | Seals decision-time replay snapshots and boundary summaries with integrity hashes. | Live replay is available through /replay-live/{{decision_id}} and compare through /replay-live/{{decision_id}}/compare. |
Event / User / Agent / Workflow / API
|
v
Decision Request
|
v
Enterprise Decision Runtime
|
+-- Decision Context Builder
+-- Decision Type Classifier
+-- Decision Strategy Selector
+-- Risk and Materiality Engine
+-- Value Impact Engine
+-- Recommendation Evaluator
+-- Policy Constraint Adapter
+-- Evidence Evaluation Adapter
+-- Human Authority Adapter
+-- Next Best Action Engine
+-- Decision Explanation Engine
+-- Decision Ledger
+-- Decision Replay Adapter
+-- Learning Signal Publisher
|
v
Decision Outcome
| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/iaf/enterprise-decision-runtime/contract | Return runtime responsibilities, supported decision types, SLO, and API contract. | Runtime definition. |
POST /api/iaf/enterprise-decision-runtime/execute | Build a deterministic decision envelope and replay package. | Stateless execution path. |
POST /api/iaf/enterprise-decision-runtime/execute-live | Execute through live platform boundaries and persist proof records. | Authoritative production path. |
GET /api/iaf/enterprise-decision-runtime/replay-live/{decision_id} | Retrieve persisted live replay envelope for a decision. | Replay and audit. |
GET /api/iaf/enterprise-decision-runtime/replay-live/{decision_id}/compare | Compare replay state against persisted live records. | Replay integrity check. |
POST /api/iaf/enterprise-decision-runtime/approvals/{decision_id}/transition | Move a decision approval contract through approve, reject, assign, or escalate transitions. | Human authority boundary. |
GET /api/iaf/enterprise-decision-runtime/production-certification-live | Validate runtime certification against live persisted records. | Operational readiness. |
| Strategy | Use | Control Position |
|---|---|---|
| Deterministic-first | Exact matching, thresholds, tolerances, authority, source-system status. | Default for regulated finance execution. |
| Hybrid | Structured checks plus narrative explanation, ambiguous exception handling, or case summarization. | Allowed when deterministic gates remain authoritative. |
| Human-led | High-value, sensitive, control-relevant, or judgment-heavy decisions. | Runtime routes, explains, records, and waits for approval. |
| Simulation-led | Scenario comparison, forecast tradeoffs, cash impact, and policy-change impact analysis. | No operational write-back unless promoted through policy and approval. |
Returns the action boundary. The Decision Runtime can recommend, escalate, or hold only inside that boundary.
Provides evidence packs and hashes used to determine confidence, supportability, and replay readiness.
Executes domain skills selected by the workflow plan and records tool invocation proof.
Persisted replay and telemetry prove what ran, how long it took, which tools were called, and what outcome was produced.
A duplicate-payment risk event requests a hold recommendation. The runtime assembles invoice context, evidence items, policy state, selected skill output, approval requirements, value estimate, and replay proof. The resulting decision can recommend the hold, block payment release, route supervisor approval, and persist a replayable decision record.
{
"decision": "hold_and_escalate",
"allowed_to_execute": false,
"human_approval_required": true,
"policy_result": "REQUIRE_HUMAN_APPROVAL",
"evidence_complete": true,
"platform_boundaries": {
"policy": "enterprise_policy_intelligence_runtime",
"evidence": "EvidencePack",
"ledger": "DecisionLogRecord",
"approval": "DecisionContractRecord",
"replay": "ReplayManifest/ReplayRun/ReplayStep"
}
}
Agents may propose recommendations and skills may generate signals, but the Decision Runtime owns the governed conversion from recommendation to operational next step. No material action should bypass policy, evidence, approval, ledger, and replay checks at the backend action layer.
The Evidence Intelligence Runtime is the proof layer for Sphere. It discovers, retrieves, validates, ranks, links, explains, packages, and preserves the evidence required to support recommendations, decisions, controls, approvals, escalations, and governed system actions.
The Policy Runtime determines what is allowed. The Decision Runtime determines what should happen next. The Evidence Runtime proves why a recommendation or decision is credible. It prevents unsupported agent claims by attaching source-linked, validated, and replayable evidence to material recommendations and actions.
It does not replace source systems, document management, identity, policy, or final business decisioning. It references and packages evidence from authoritative systems, preserves lineage, evaluates sufficiency, and exposes role-appropriate proof to runtime consumers.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | evidence_intelligence_runtime.py and evidence_intelligence_fabric.py |
Certified by evidence runtime live-source, world-class differentiator, and runtime certification tests. |
| API surface | /api/eir/* and /api/evidence/* |
Covers contract, search, pack, decision-ready pack, provenance, graph, validate, lineage, trust score, ranking, compare, replay, KPIs, and certification. |
| Persisted evidence | EvidencePack and evidence artifact tables |
Runtime can load persisted evidence packs, compute integrity coverage, and distinguish persisted packs from compatibility records. |
| Decision-ready packs | POST /api/eir/decision-ready-pack |
Produces role-scoped evidence packs for analyst, supervisor, auditor, and executive consumption. |
| Provenance and integrity | Provenance manifests, signature verification, content hashes, lineage records, and replay references. | Implemented through /api/eir/provenance/{{case_id}}, /api/eir/provenance/verify, and evidence vault verification/export endpoints. |
| Evidence intelligence | Trust scoring, continuous trust scoring, evidence graph, ranking, source-family normalization, and conflict comparison. | Operational APIs include /api/eir/trust-score, /continuous-trust, /graph, /rank, and /compare. |
| Operational surfaces | Evidence Vault, Decision Replay Studio, and Policy Library | Evidence is consumed by case drawers, decision records, assurance packets, replay views, and policy/approval flows. |
Agent / User / Decision Runtime / Policy Runtime / Workflow
|
v
Evidence Request
|
v
Evidence Intelligence Runtime
|
+-- Evidence Discovery Engine
+-- Evidence Connector Layer
+-- Evidence Normalization Engine
+-- Evidence Validation Engine
+-- Evidence Sufficiency Engine
+-- Evidence Conflict Detector
+-- Evidence Ranking Engine
+-- Evidence Pack Builder
+-- Evidence Lineage Store
+-- Evidence Access Control Adapter
+-- Evidence Replay Adapter
+-- Evidence Observability
|
v
Evidence Pack / Evidence Status / Missing Evidence / Lineage
| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/eir/contract | Return runtime responsibilities, contract, and production gates. | Runtime definition. |
POST /api/eir/search | Search evidence by query, case, or source. | Discovery. |
POST /api/eir/pack | Build a case evidence pack. | Evidence packaging. |
POST /api/eir/decision-ready-pack | Build a role-scoped decision-ready evidence pack. | Decision and approval consumption. |
GET /api/eir/provenance/{case_id} | Return the provenance manifest for a case. | Lineage and audit. |
POST /api/eir/provenance/verify | Verify a provenance manifest. | Integrity validation. |
GET /api/eir/graph/{case_id} | Return evidence graph relationships. | Evidence intelligence. |
POST /api/eir/validate | Validate case evidence against required evidence. | Sufficiency and quality. |
GET /api/eir/lineage/{case_id} | Return lineage for evidence records. | Replay and audit. |
GET /api/eir/trust-score/{case_id} | Return evidence trust score. | Trust scoring. |
GET /api/eir/replay/{case_id} | Return replayable evidence context. | Replay adapter. |
GET /api/evidence/packs | List persisted evidence packs from the evidence vault. | Operational evidence store. |
| Status | Meaning | Runtime Constraint |
|---|---|---|
complete | All required evidence is available. | Eligible for the configured decision purpose. |
complete_for_recommendation | Enough proof for recommendation, not execution. | Execution remains blocked or approval-gated. |
partial | Some required evidence is missing. | Decision must disclose gaps. |
missing | Required evidence unavailable. | Request evidence or require review. |
conflicting | Sources disagree. | Execution blocked until resolved. |
stale | Evidence freshness no longer satisfies policy. | Refresh required before high-risk execution. |
restricted | Actor lacks entitlement. | Mask or deny the evidence item. |
untrusted | Source is not authoritative enough. | Use only as supporting context. |
Defines evidence requirements and consumes sufficiency status before allowing action.
Uses evidence packs to determine whether a recommendation is supportable and what action is allowed next.
Agents and skills ground material claims in evidence IDs, packs, source records, and lineage.
Reconstructs evidence state using pack IDs, source references, hashes, timestamps, and decision IDs.
A duplicate-payment case requires current invoice, prior candidate, supplier master, payment history, payment status, policy reference, and approval state. The runtime can mark the pack complete for recommendation while explicitly blocking execution until approval evidence is present.
{
"evidence_pack_id": "evp_001928",
"status": "complete_for_recommendation",
"sufficiency": {
"recommendation": true,
"approval": true,
"execution": false,
"audit": true
},
"missing_evidence": ["supervisor_approval"],
"lineage_pointer": "lineage://evidence/evp_001928"
}
Evidence must be assembled and validated before material recommendations are treated as decision-ready. A value shown in a user interface is not evidence unless it is linked to a source record, validation state, freshness status, lineage, and evidence pack reference.
The Enterprise Context Runtime is the contextual intelligence layer for Sphere. It gathers, normalizes, enriches, governs, optimizes, and serves the business context required by agents, policies, decisions, evidence packs, workflows, analytics, supervisors, and executives.
Evidence proves specific claims. Context frames the complete business situation around those claims. The Context Runtime answers what the platform, user, workflow, or model is allowed to know before a recommendation, evidence pack, policy decision, or business decision is produced.
The runtime does not replace SAP, Ariba, ServiceNow, Databricks, Foundry, UDP, identity, evidence, policy, or final decisioning. It creates a governed context object from those sources and platform runtimes so downstream consumers do not each invent their own interpretation of the same case.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_context_runtime.py |
Certified by enterprise context runtime certification, live-source, production certification, and context quality tests. |
| API surface | /api/ecr/* |
Provides contract, build, preview, rank, compress, explain, graph, quality, governance, sources, observability, KPI, and certification endpoints. |
| Context audit surface | /api/iaf/context-runtime/* |
Exposes context operations, audit cases, lineage, usage, skills/policies, control plane, ontology, judgment, learning, and missing-context simulation. |
| CREST reconstruction | /crest/context/build and /api/iaf/crest/context/build |
Builds reconstructed context from CREST entities, graph edges, decision links, skills, ontology, and knowledge metrics. |
| Persisted context | ResolvedContext, ResolvedContextSnapshot, and decision context hashes |
Decision and payment services persist context snapshots and replay verifies context/source snapshot hashes. |
| Context intelligence | Ranking, compression, explanation, context graph, quality scoring, governance checks, and source catalog. | Implemented through rank_context, compress_context, explain_context, context_graph, context_quality, and context_governance. |
| Operational surfaces | Context Graph, CREST Context Studio, Context Engineering, and Context Audit Console | Context is visible as a platform runtime, not only as page-local data. |
User / Agent / Workflow / Evidence / Policy / Decision
|
v
Context Request
|
v
Enterprise Context Runtime
|
+-- Context Request Router
+-- Source Connector Adapter
+-- Domain Normalization Engine
+-- Business Ontology Mapper
+-- Source Catalog and Process Lifecycle
+-- Context Enrichment Engine
+-- Identity and Entitlement Adapter
+-- Data Masking and Redaction Adapter
+-- Freshness and Source Health Engine
+-- Context Ranking and Compression
+-- Context Graph and CREST Reconstruction
+-- Context Snapshot and Lineage Store
+-- Context Observability
|
v
Governed Business Context Object
| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/ecr/contract | Return runtime responsibilities, components, sources, process lifecycles, and certification endpoints. | Runtime definition. |
POST /api/ecr/context/build | Build a governed context pack, preferring live persisted source I/O with safe fallback. | Context assembly. |
POST /api/ecr/context/preview | Preview context structure and scope before downstream use. | Context review. |
POST /api/ecr/context/rank | Rank context by relevance and decision utility. | Context optimization. |
POST /api/ecr/context/compress | Compress context to a bounded set of high-value items. | Model and latency control. |
POST /api/ecr/context/explain | Explain what context is included and why. | User and agent transparency. |
POST /api/ecr/context/graph | Return context graph nodes, edges, and relationship summary. | Graph reconstruction. |
POST /api/ecr/context/quality | Score completeness, freshness, source coverage, and decision readiness. | Context quality. |
POST /api/ecr/context/governance | Evaluate redaction, authority, external sharing, and policy compliance. | Context governance. |
GET /api/ecr/sources | Return approved source catalog, optionally scoped by mission. | Source registry. |
GET /api/ecr/executive-console | Return cross-runtime context console summary. | Executive context. |
GET /api/ecr/observability-contract | Return context observability and operational measurement contract. | Runtime operations. |
POST /crest/context/build | Build CREST context from enterprise graph and decision-link assets. | Context reconstruction. |
GET /api/iaf/context-runtime/audit/cases/{entity_id}/lineage | Return case context lineage for audit and replay. | Lineage. |
| Context Type | Purpose | Example Runtime Consumer |
|---|---|---|
case | Full business situation around one case. | Case drawer, Decision Runtime, replay. |
transaction | Invoice, payment, journal, PO, receipt, or reconciliation state. | Evidence Runtime and Skill Runtime. |
entity | Supplier, customer, account, legal entity, cost center, or business unit. | Agent Runtime and mission workbench. |
mission | Queue, process, lifecycle, and operating state for P2P, O2C, R2R, Treasury, FP&A, or Tax. | Supervisor control plane. |
ai | Prompt-safe, role-scoped context for an agent or external model target. | Ask Sphere and model gateway. |
replay | Snapshot and hash set used to reconstruct prior decisions. | Replay Runtime and assurance views. |
Consumes context to discover which evidence should be assembled, validated, and packaged.
Uses context fields such as role, amount, mission, data sensitivity, source state, and requested action.
Uses context to classify decision type, select strategy, evaluate risk/value, and generate next best action.
Receives scoped, governed context packs instead of independently fetching unmanaged source data.
Reconstructs enterprise context through entities, graph edges, decision links, ontology, skills, and knowledge metrics.
Verifies context snapshots and source hashes so later review can reconstruct the original business situation.
For a duplicate-payment case, the runtime frames the invoice as more than an AP record. It becomes a P2P exception with supplier context, payment status, prior-payment context, process stage, risk, SLA posture, policy relevance, evidence references, role authority, and source lineage.
{
"context_id": "ECR-p2p-INV-LIVE-DUP-1778594510",
"case_id": "INV-LIVE-DUP-1778594510",
"mission": "p2p",
"role": "p2p_analyst",
"process_awareness": {
"process": "purchase_to_pay",
"stage": "exception_review"
},
"security": {
"direct_sor_access": false,
"redaction_required": true,
"authority": "recommend_only",
"data_boundary": "minimum_required_context",
"rbac": true,
"abac": true,
"prompt_injection_protection": true
},
"source_catalog": ["SAP ECC", "SAP S/4HANA", "SAP Ariba", "Databricks", "Policy Runtime", "Evidence Runtime"]
}
The Context Runtime is the source of governed business framing. If a page, agent, policy check, evidence pack, or decision requires business situation awareness, it should consume the shared context pack rather than assembling an isolated interpretation from raw APIs.
The Enterprise Agent Runtime is the controlled execution layer for Sphere agents. It governs how agents are registered, planned, invoked, scoped, tooled, constrained, monitored, certified, lifecycle-managed, and replayed.
Context defines what an agent may know. Evidence proves what the agent can rely on. Policy determines what is allowed. Decisioning determines what should happen next. The Agent Runtime defines how agents participate in that chain without becoming uncontrolled scripts, prompts, or source-system actors.
The runtime does not own policy authoring, source-system write execution, model-provider infrastructure, evidence storage, or final business authority. It owns the governed agent control plane: registration, planning, execution gates, tool permission contracts, model lineage, collaboration, certification, observability, lifecycle state, and replay packages.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_agent_runtime.py |
Certified by enterprise agent runtime certification and production gate tests. |
| API surface | /api/ear/* |
Provides contract, registry, register, plan, execute, collaborate, certify, promotion gate, learning feedback, suspend, retire, console, observability, KPI, and certification endpoints. |
| Platform registry | IRISAgentRegistry, AgentDefinition, AgentDeployment, AgentPolicyBinding, and AgentEvidenceContract |
Separates canonical agent identity, tenant activation, policy binding, and evidence/replay requirements. |
| Execution substrate | AgentExecution, AgentExecutionTelemetry, ToolInvocation, and replay manifests |
Runtime executions carry execution IDs, hashes, tool lineage, model lineage, evidence package, replay timeline, and telemetry. |
| Operational gates | Readiness gate, policy gate, evidence gate, decision gate, tool permission gate, human boundary, and lifecycle controls. | Production certification asserts all gates for a high-risk duplicate-invoice agent execution. |
| Agent operations surfaces | Agent Inventory, Agentic Workforce, Skill Fabric, and Agent Governance Center | Agent health, readiness, policy binding, evidence, execution history, and governance can be inspected from live UI surfaces. |
| Measured posture | world_class_certification() and production_certification() |
The runtime exposes measured readiness gaps and does not claim full world-class status unless production gates and persisted execution evidence support it. |
User / Event / Workflow / Schedule / API
|
v
Agent Invocation Request
|
v
Enterprise Agent Runtime
|
+-- Agent Registry
+-- Agent Manifest and Readiness Validator
+-- Invocation Router
+-- Context Injection Adapter
+-- Planning and Task Decomposition
+-- Tool Authorization Engine
+-- Policy Enforcement Adapter
+-- Evidence Attachment Adapter
+-- Agent Execution Boundary
+-- Decision Handoff Adapter
+-- Human Handoff Adapter
+-- Agent Memory and Learning Adapter
+-- Agent Observability
+-- Agent Replay Recorder
|
v
Recommendation / Explanation / Draft / Evidence Request / Escalation / Decision Request / Action Proposal
/api/ear/agents/register.| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/ear/contract | Return runtime scope, ownership, operating model, autonomy contract, integrations, and APIs. | Runtime definition. |
GET /api/ear/registry | Return registered agents with lifecycle state, declared controls, tools, permissions, and certification posture. | Agent registry. |
POST /api/ear/agents/register | Register an agent with ownership, autonomy, tools, models, skills, policies, dependencies, SLA, and version. | Registration and manifest validation. |
POST /api/ear/agents/plan | Create a cost-aware and time-aware task plan with required runtime gates. | Planning. |
POST /api/ear/agents/execute | Execute an agent within readiness, policy, evidence, decision, tool, and human-boundary gates. | Governed execution. |
POST /api/ear/agents/collaborate | Assemble peer-review and consensus team for high-risk or critical work. | Agent collaboration. |
POST /api/ear/agents/certify | Score agent readiness and return promotion state, blockers, and governance checks. | Certification. |
POST /api/ear/agents/{agent_id}/promotion-gate | Evaluate whether an agent can progress to the target lifecycle state. | Lifecycle gate. |
POST /api/ear/agents/learning-feedback | Record human feedback, learning, plan-change signal, and evidence reference. | Learning adapter. |
POST /api/ear/agents/{agent_id}/suspend | Suspend an agent and record the control reason. | Operational control. |
POST /api/ear/agents/{agent_id}/retire | Retire an agent and require archive of execution/replay/certification history. | Lifecycle closure. |
GET /api/ear/observability-contract | Return agent metrics, traces, alerts, and SLOs. | Runtime observability. |
GET /api/ear/production-certification | Run production certification gates against a representative high-risk execution contract. | Release gate. |
| Output | Meaning | Required Boundary |
|---|---|---|
recommendation | Agent proposes an action or next step. | Evidence reference, policy context, decision handoff for material action. |
explanation | Agent explains structured runtime outputs. | No new unsupported facts; cite context, evidence, policy, or decision objects. |
draft | Agent prepares a message, note, or action payload. | Human review unless policy allows direct administrative send. |
evidence_request | Agent identifies missing proof. | Evidence Runtime request or human evidence collection task. |
escalation_request | Agent routes high-risk or blocked work. | Supervisor, controller, control owner, treasury approver, or other role queue. |
decision_request | Agent asks Decision Runtime to evaluate next best action. | Decision ID, policy decision, evidence pack, and replay reference. |
action_proposal | Agent proposes source-system or workflow action. | Policy, evidence, decision, human approval, and integration write-back gates. |
| Autonomy Level | Runtime Meaning | Execution Constraint |
|---|---|---|
observe | Agent can monitor and report. | No recommendations or actions without escalation. |
recommend | Agent can recommend or explain. | No external action execution. |
assist | Agent can draft and prepare work. | Human review before controlled action. |
execute_with_approval | Agent can prepare execution after approval. | Approval and decision gates required. |
autonomous_within_policy | Agent can execute only within explicit low-risk policy boundaries. | Policy, evidence, decision, observability, and replay gates remain mandatory. |
Provides scoped context packages so agents do not fetch unrestricted raw source data.
Supplies evidence packs and evidence gates for material recommendations.
Constrains invocation, tool use, external sharing, action proposal, memory creation, and write-back requests.
Evaluates agent recommendations before business actions are allowed.
Provides deterministic and hybrid business capabilities that agents can invoke under permissioned tool contracts.
Records execution hash, timeline, gates, tool/model lineage, telemetry, collaboration, and final output.
A P2P duplicate-invoice agent can assess a high-risk candidate, generate a hold recommendation, attach evidence, and request a decision. The runtime records that external action was requested but not executed until policy, evidence, decision, and human gates clear.
{
"operation": "ExecuteAgent",
"agent_id": "p2p_duplicate_invoice_agent",
"reasoning_completed": true,
"external_action_requested": true,
"external_action_executed": false,
"reasoning_execution_separated": true,
"gate": {
"policy_gate": {"required": true},
"evidence_gate": {"required": true, "status": "passed"},
"decision_gate": {"required": true},
"tool_permission_gate": {"status": "passed"},
"human_boundary": "approval_required_before_external_action"
},
"replay": {
"immutable_after_finalization": true,
"timeline": ["agent_registered", "context_loaded", "policy_prechecked", "evidence_checked", "tools_invoked", "recommendation_generated", "decision_gate_applied", "human_boundary_recorded"]
}
}
external_action_executed=false until gates clear.No material agent should execute outside the runtime control plane. Agents can reason and recommend, but source-system action requires context, evidence, policy, decision, tool authorization, human boundary, observability, and replay records at the backend action layer.
The Enterprise Skill Runtime is the reusable business-capability execution layer for Sphere. It provides governed, versioned, observable, evidence-producing skills that agents, workflows, decisions, policies, evidence packs, and user experiences can invoke consistently.
Agents coordinate and reason. Skills perform defined business capabilities with schema-bound inputs, outputs, policies, evidence, versioning, observability, and replay. This keeps finance logic out of prompts and makes reusable capabilities inspectable by architects, operators, control owners, and auditors.
The runtime does not own agent reasoning, final decisions, policy authoring, source-system authority, evidence storage, or workflow orchestration. It owns the governed execution contract for reusable skills and the Skill Fabric integration that turns domain logic into callable platform capabilities.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_skill_runtime.py |
Certified by enterprise skill runtime tests covering contract, registry, marketplace, composition, execution, durable history, certification, and production gates. |
| Skill Fabric service | skill_fabric_service.py and skill_runtime_logic.py |
Executes concrete finance skills including duplicate invoice detection, 3-way match, GRIR, price/quantity variance, vendor risk, payment terms, discount capture, R2R, FP&A, Treasury, and O2C contributors. |
| API surface | /api/esr/* and /api/iaf/skills/* |
ESR provides enterprise lifecycle/governance. Skill Fabric provides registry, dependency readiness, execution, lifecycle, overlays, quality, graph, lineage, and durable execution surfaces. |
| Skill contracts | core/enterprise_skill_contract_runtime.py and filesystem-backed skill.yaml packages |
Skill manifests compile provider-neutral skill context, input/output contracts, policy bindings, evidence requirements, role variants, and package metadata. |
| Durable execution | SkillExecutionRecord and ToolInvocation |
Durable execution stores skill ID, mission, decision reference, role, status, evidence hash, input/output hashes, selection metadata, execution metadata, and replay data. |
| Governance and gates | Skill governance gate, policy gate, audit gate, budget enforcement, source-adapter contract, and fabric gate before durable execution. | Live adapter skills require payloads and block rather than fabricate records when SAP, Ariba, Microsoft Graph, or Databricks payloads are absent. |
| Operational surfaces | Skill Fabric, Skills Registry, Skill Reality Control Plane, and Skill Fabric Introduction | Users can inspect skill contracts, dependency readiness, lifecycle state, source bindings, execution history, and replay links. |
iaf_skill_execution_records with evidence/input/output hashes and execution metadata.Agent / Workflow / Decision Runtime / Evidence Runtime / UI / API
|
v
Skill Invocation Request
|
v
Enterprise Skill Runtime
|
+-- Skill Registry
+-- Skill Contract Validator
+-- Discovery and Marketplace
+-- Composition Planner
+-- Input Validation
+-- Governance Gate
+-- Skill Execution Engine
+-- Deterministic Logic Executor
+-- Integration Adapter Boundary
+-- Model / AI Adapter
+-- Evidence Output Adapter
+-- Output Quality Scoring
+-- Budget and Reliability Monitor
+-- Durable Execution Recorder
+-- Skill Replay Recorder
|
v
Score / Match Result / Classification / Calculation / Validation / Decision Signal / Evidence Item / Simulation Result
| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/esr/contract | Return ESR scope, ownership, taxonomy, relationships, differentiators, and integration contract. | Runtime definition. |
GET /api/esr/registry | Return enterprise skill registry and registry controls. | Skill registry. |
POST /api/esr/skills/register | Register a governed skill contract. | Registration. |
POST /api/esr/skills/discover | Find skills by mission, domain, category, query, capability, and caller. | Discovery. |
POST /api/esr/marketplace | Return searchable marketplace results with dependency visualization, usage analytics, ratings, and usage summary. | Marketplace. |
POST /api/esr/skills/compose | Create sequential or parallel skill composition plan. | Composition. |
POST /api/esr/skills/run-composition | Execute a reusable multi-skill composition plan with replay. | Composition execution. |
POST /api/esr/skills/execute | Execute a skill with governance, certification, evidence, quality, budget, observability, and replay output. | Skill execution. |
POST /api/esr/skills/execute-durable | Execute with fabric gate and persist SkillExecutionRecord. | Durable execution. |
GET /api/esr/skills/executions | Read durable execution history by skill ID. | Replay and audit. |
POST /api/esr/skills/certify | Score skill readiness and governance board checks. | Certification. |
POST /api/esr/skills/{skill_id}/governance-gate | Evaluate whether skill can move to target lifecycle state. | Governance gate. |
POST /api/esr/fabric/load | Import filesystem-backed Skill Fabric catalog into ESR. | Skill Fabric integration. |
GET /api/iaf/skills/registry/{skill_id} | Inspect concrete Skill Fabric contract. | Operational contract. |
POST /api/iaf/skills/execute | Execute concrete Skill Fabric skill and emit tool invocation log. | Domain skill execution. |
GET /api/iaf/skills/executions | Read Skill Fabric execution history. | Skill replay. |
| Type | Implemented Examples | Primary Output |
|---|---|---|
| Matching | finance.p2p.duplicate_invoice_detection, finance.p2p.3way_match_resolution, reconciliation contributors. | Match score, reasons, candidate, variance. |
| Scoring | Duplicate payment, vendor risk, close task risk, forecast confidence, liquidity assessment. | Risk, priority, confidence, materiality. |
| Validation | Invoice math integrity, payment terms, currency, vendor master, posting control, policy compliance. | Validation result and failed controls. |
| Calculation | GRIR variance, price/quantity variance, discount capture, cash forecast impact, KPI delta. | Calculated exposure, variance, value. |
| Extraction / Explanation | Evidence pack assembly, historical decision context, executive explanation, invoice classification. | Structured context, narrative, evidence refs. |
| Integration | sap_read, ariba_read, databricks_query, msgraph_read. | Live adapter payload or blocked status. |
| Mode | Use | Control Posture |
|---|---|---|
deterministic | Thresholds, calculations, exact matches, schema validation. | Preferred for financial controls and audit-sensitive checks. |
deterministic_first | Duplicate matching, 3-way match, GRIR, payment terms, posting control. | Structured logic dominates; explanation may be added after. |
integration_adapter | SAP, Ariba, Databricks, Microsoft Graph read adapters. | Live payload required; no fabricated fallback. |
ai_assisted | Classification, explanation, executive summary, document-language interpretation. | Policy-gated, output-schema validated, evidence-aware. |
hybrid | Domain contributors combining deterministic checks, model support, context, policy, and evidence. | Replay must bind skill version, source refs, model/policy versions, and output hashes. |
simulation | Scenario, cash, forecast, value, and transformation calculations. | Simulation output is decision input, not direct execution authority. |
Agents discover and invoke certified skills instead of embedding finance logic in prompts.
Consumes skill outputs as decision signals, selected skill IDs, replay bindings, and skill result payloads.
Provides normalized context and scoped source data required by skills.
Converts skill outputs into evidence items, evidence hashes, and evidence pack contributors.
Gates sensitive data use, model use, execution eligibility, source dependency, and learning capture.
Tracks skill version, input/output hashes, evidence hash, policy gate, source calls, latency, cost, and replay pointer.
The duplicate invoice capability runs as a reusable skill rather than prompt-only agent logic. It produces a structured score, risk level, match reasons, evidence hash, business outcome, replay ID, and execution hash.
{
"operation": "ExecuteSkill",
"skill_id": "duplicate_invoice_detection",
"skill_version": "1.0.0",
"outputs": {
"status": "completed",
"duplicate_risk_score": 0.98,
"risk_level": "high",
"match_reasons": ["same_supplier", "same_amount", "similar_invoice_number", "payment_window_overlap"]
},
"evidence": {
"evidence_hash": "sha256:...",
"produced_by": "enterprise_skill_runtime"
},
"quality": {
"trust_score": 0.9
},
"replay": {
"immutable_after_finalization": true
}
}
Business logic belongs in reusable skill contracts. Agents may orchestrate, explain, and recommend, but matching, scoring, validation, calculation, extraction, simulation, and control checks should run through the Skill Runtime so outputs are versioned, tested, observable, evidence-ready, and replayable.
The Enterprise Orchestration Runtime is the coordination layer for Sphere missions. It governs how triggers, cases, context, evidence, skills, agents, policies, decisions, human approval, workflow actions, events, and source-system handoffs move from intent to controlled outcome.
The implemented service is named EnterpriseIntelligenceOrchestrationRuntime. In the platform
runtime stack, it is the enterprise orchestration capability: it creates the execution plan, chooses
participating runtimes, binds context/evidence/skills/model route, applies policy gates, creates human wait
states, records observability, and seals replay.
The runtime does not decide business outcomes, author policies, own evidence, or bypass systems of record. Decisioning remains with the Decision Runtime, governance remains with Policy Runtime, evidence remains with Evidence Runtime, and source-system updates flow through controlled ACT or integration action paths.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime control plane | enterprise_intelligence_orchestration_runtime.py |
Plans and executes cross-runtime flows across context, policy, skill, model routing, evidence, decision, human wait states, replay, and learning. |
| EIOR API surface | /api/eior/* |
Exposes runtime contract, runtime/model/skill registries, workflow planning, execution, execution status, cancellation, replay, executive ops console, and production certification. |
| Mission ACT orchestration | act_orchestration.py, mission_act.py, and config/act_workflows.yaml |
Executes deterministic mission actions from YAML workflow definitions with role checks, policy hooks, workflow/step persistence, evidence creation, canonical events, and SOR action records. |
| Workflow persistence | WorkflowRunRecord, WorkflowStepRecord, WorkflowPolicyResolutionRecord, FlowTraceRecord, ExecutionLedger, and SorActionRecord |
Mission ACT and universal action execution record workflow state, step state, evidence hashes, policy resolution, flow trace, ledgers, and controlled source-system writeback disposition. |
| Event and failure handling | enterprise_event_runtime.py, governance_outbox.py, and iaf_event_dead_letters |
Event runtime validates, routes, observes, and dead-letters events; governance outbox retries with exponential backoff and records retry/dead-letter metrics. |
| Certification | tests/test_runtime_cert_orchestration_and_evidence_gap_closure.py |
Validates measured orchestration certification, production gates, bounded attestation reads, hub-spoke collaboration disclosure, replay graph, policy fail-closed behavior, and ops console output. |
| Operational surfaces | Active Missions, Mission Command Center, Observability, and Replay Theater | Users can inspect mission state, orchestration timelines, operational telemetry, and replay lineage across runtime steps. |
Event / User / Schedule / API / Source-System Change
|
v
Mission or Workflow Trigger
|
v
Enterprise Orchestration Runtime
|
+-- Trigger Router
+-- Runtime and Skill Registry
+-- Workflow Plan Builder
+-- Context Envelope Builder
+-- Evidence Envelope Binder
+-- Skill and Model Route Selector
+-- Runtime Invocation Coordinator
+-- Policy Gate Coordinator
+-- Decision Gate Coordinator
+-- Human Wait State Coordinator
+-- Mission ACT Workflow Executor
+-- Integration Action Coordinator
+-- Retry / Cancel / Dead-Letter Handler
+-- Orchestration Ledger
+-- Replay Recorder
+-- Observability Publisher
|
v
Completed / Waiting For Human / Waiting For Evidence / Blocked / Cancelled / Failed Safe / Replayed
| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/eior/contract | Return runtime responsibility, owned capabilities, separation of duties, and certification endpoints. | Runtime definition. |
GET /api/eior/registries/runtimes | Return participating runtime registry, owners, SLAs, capabilities, APIs, and dependencies. | Runtime selection. |
GET /api/eior/registries/models | Return approved deterministic, frontier, sovereign/private, and local model routes. | Model routing. |
GET /api/eior/registries/skills | Return mission-scoped skill contracts available for orchestration. | Skill selection. |
POST /api/eior/workflows/plan | Create an execution plan with context envelope, evidence envelope, skill package, model route, steps, human boundary, and replay contract. | Workflow planning. |
POST /api/eior/workflows/execute | Execute planned steps, evaluate policy, create step outputs, collaboration state, decision memory, learning signal, observability, and replay hash. | Cross-runtime execution. |
GET /api/eior/executions/{execution_id} | Return latest persisted plan, execution, or cancellation state with attestation hash. | Status. |
POST /api/eior/executions/{execution_id}/cancel | Cancel an execution and persist cancellation attestation. | Safe termination. |
POST /api/eior/executions/{execution_id}/replay | Reconstruct plan and execution timeline from persisted attestations. | Replay. |
GET /api/eior/executive-ops-console | Aggregate recent plan/execution/cancel history, compliance rate, human wait count, latency, cost, and consensus rate. | Operations. |
GET /api/eior/production-certification | Run bounded production gates against a real plan execution contract. | Release gate. |
POST /api/iaf/actions/simulate | Simulate universal action effects without mutating source-system state. | Action simulation. |
POST /api/iaf/actions/execute | Execute a governed action with policy proof, evidence hash, ledger, and writeback disposition. | Controlled action. |
POST /api/iaf/missions/{mission_id}/entity/{entity_id}/act | Run a YAML-defined ACT workflow for a mission/entity/action. | Mission action workflow. |
GET /api/iaf/missions/{mission_id}/act/workflows | List configured mission ACT workflows and allowed roles. | Workflow registry. |
GET /api/iaf/missions/{mission_id}/act/history | Return recent mission workflow runs with actor, role, status, timestamps, and evidence hash. | Workflow history. |
GET /api/iaf/missions/{mission_id}/act/{workflow_id}/status | Return persisted workflow run and step state. | Workflow state. |
| Pattern | Implemented Form | Control Point |
|---|---|---|
| Sequential orchestration | EIOR step graph: context, policy, skill, model, evidence, decision, human wait, controlled execution, replay, learning. | Plan hash and step output hashes. |
| Deterministic ACT workflow | config/act_workflows.yaml defines mission/action steps such as permission validation, policy compliance, journal posting, event emission, evidence bundle, and action log. | Workflow run and step records. |
| Policy-gated orchestration | PolicyAsCodeRuntime.evaluate can produce DENY, REQUIRES_MORE_EVIDENCE, REQUIRES_HUMAN_APPROVAL, or allow execution path. | Sibling dispatch and controlled execution boundary. |
| Human-in-the-loop orchestration | High-risk or write-bound actions enter human_wait_state or Mission ACT approval queues rather than executing directly. | Human boundary and role authority. |
| Evidence-gated orchestration | Evidence envelope, evidence hash, and evidence bundle creation determine whether recommendation, approval, or execution can proceed. | Evidence pack and replay lineage. |
| Event-driven orchestration | Event Runtime handles event validation, source metadata, route decisions, workflow refs, dead letters, and metrics. | Event fabric and dead-letter records. |
| Retry and compensation | Step retry policy is declared in EIOR; governance outbox retries with exponential backoff; spine engine records compensation completion. | Retry counters, dead-letter state, compensation result. |
| Replay-oriented orchestration | EIOR replay returns timeline records and replay hash; ACT records evidence hash, workflow history, ledger, and step status. | Replay contract and attestation hash. |
| Outcome | Meaning | Implemented Signal |
|---|---|---|
completed | Governed plan or workflow completed. | EIOR status or WorkflowRunRecord status. |
waiting_for_human | Policy, risk, or write boundary requires approval/review. | EIOR final status and human wait metric. |
waiting_for_evidence | Policy requires additional evidence before continuation. | EIOR policy decision REQUIRES_MORE_EVIDENCE. |
blocked | Policy denied or blocked sibling dispatch / controlled action. | EIOR sibling-agent policy and policy block metric. |
cancelled | User or system cancelled execution. | eior_cancel attestation with previous status and cancel hash. |
failed_safe | Runtime cannot proceed safely. | Workflow error state, outbox dead-letter, event dead-letter, or bounded degraded certification. |
simulated | Action impact calculated without source-system mutation. | /api/iaf/actions/simulate response with simulated flag and impact fields. |
EIOR builds or references governed context before skills, evidence, policy, and decisions use case state.
Evidence envelopes, evidence hashes, evidence bundles, and evidence refs travel through plan, action, decision memory, and replay.
Skill registry and compiled skill packages become orchestration steps rather than embedded workflow logic.
Agents participate through shared context and sibling dispatch policy; EIOR remains the process control plane.
Policy decisions gate sibling dispatch, evidence wait, human wait, and controlled source-system action.
Decision Runtime owns business recommendation; Orchestration Runtime owns the process path around that decision.
Validated events, workflow refs, metrics, retries, and dead letters connect mission triggers and downstream operations.
Source-system writeback remains behind policy proof, evidence hash, execution ledger, SOR action record, and writeback disposition.
A high-risk P2P duplicate payment case runs through orchestration as a plan rather than disconnected page calls. The runtime coordinates context, policy, skill, model route, evidence, decision, human wait, replay, and learning while preserving a controlled action boundary.
{
"runtime": "enterprise_intelligence_orchestration_runtime",
"case_id": "INV-LIVE-DUP-1778594510",
"mission": "p2p",
"proposed_action": "hold_payment",
"control_plane_boundary": "EIOR orchestrates; Decision Runtime decides; Policy Runtime governs",
"runtime_selection": [
"enterprise_context_runtime",
"enterprise_policy_intelligence_runtime",
"enterprise_skill_fabric",
"model_orchestration_gateway",
"evidence_intelligence_runtime",
"enterprise_decision_runtime",
"human_collaboration_runtime",
"enterprise_intelligence_orchestration_runtime",
"enterprise_memory_learning_runtime"
],
"human_boundary": "human_approval_required_for_write_or_policy_exception",
"replay_contract": "cross_runtime_replay_v1"
}
Orchestration is not a UI responsibility and not an agent responsibility. The platform must start, plan, gate, pause, resume, cancel, observe, and replay mission work through backend orchestration services so context, evidence, skills, policy, decisions, humans, events, and source-system actions remain coordinated and auditable.
The Enterprise Replay Runtime is the accountability and reconstruction layer for Sphere. It reconstructs how cases, decisions, evidence packs, policy checks, agent/tool activity, skill outputs, approvals, orchestration steps, and source-system actions occurred.
Replay is not raw logging. It is structured reconstruction using runtime artifact IDs, persisted replay manifests, replay runs, replay steps, policy attestations, evidence packs, decision logs, tool invocations, approval contracts, workflow records, telemetry, hashes, and source lineage.
The runtime does not make new decisions or alter historical execution state. It reconstructs what happened, validates integrity where hashes and manifests are available, projects the result by role, and supports audit, control testing, incident review, technical debugging, and continuous improvement.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Forensic replay data model | models/_replay.py |
Defines ReplayManifest, ReplayRun, ReplayStep, ReplayDiff, ReplayCertification, and SORStateComparison with indexed execution, decision, evidence-pack, entity, status, and timestamp fields. |
| Decision Replay service | decision_replay_service.py |
Provides readiness, execution explorer, execution detail, determinism health, stored replay, evidence lineage, audit pack export, deep execution drill, execution graph, risk panel, and chaos replay simulation. |
| Role-scoped replay | role_scoped_replay_service.py and replay_timeline_builder.py |
Projects replay differently for analyst, supervisor, auditor, and CFO roles; assembles timelines across policy attestations, policy evaluations, evidence packs, artifacts, violations, decision logs, and supervisory events. |
| Decision Runtime replay | enterprise_decision_runtime.py and /api/iaf/enterprise-decision-runtime/replay* |
Persists and reconstructs live decision replay envelopes with decision log, evidence pack, policy attestation, telemetry, replay manifest/run/steps, approval contract, tool invocations, and comparison output. |
| Control-plane replay | /api/iaf/control-plane/replay/{{decision_id}}, /timeline, and signed evidence export |
Returns role-scoped replay, deterministic timeline, and signed evidence bundle export for governed review. |
| Event and orchestration replay | /api/eior/executions/{{execution_id}}/replay, /api/eer/events/replay, and /api/fef/events/replay |
Reconstructs orchestration timelines and event timelines with replay hashes, filtered replay, partial replay, and event lineage. |
| User surfaces | Decision Replay Studio, Replay Theater, Replay Center, and decision drawer replay tabs | Operators can inspect replay readiness, executions, evidence lineage, graph view, risk panel, audit packs, timeline, and deterministic comparison surfaces. |
User / Auditor / Supervisor / Platform Team / API
|
v
Replay Request
|
v
Enterprise Replay Runtime
|
+-- Runtime Auth and Role Scope
+-- Replay Manifest Index
+-- Replay Run and Step Store
+-- Decision Log Adapter
+-- Evidence Pack Adapter
+-- Policy Attestation Adapter
+-- Tool Invocation Adapter
+-- Approval Contract Adapter
+-- Supervisory Timeline Adapter
+-- Orchestration Replay Adapter
+-- Event Replay Adapter
+-- Hash and Integrity Validator
+-- Replay Comparison Engine
+-- Signed Evidence Export
+-- Decision Replay Studio API
|
v
Replay Summary / Timeline / Technical Trace / Comparison / Audit Pack / Signed Evidence Bundle
| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/iaf/decision-replay/readiness | Return replay readiness, coverage, seal rate, deterministic percentage, replay success, and impact strip. | Readiness. |
GET /api/iaf/decision-replay/executions | List replayable executions with filters for agent, search, and evidence. | Execution explorer. |
GET /api/iaf/decision-replay/executions/{execution_id} | Return execution detail, linked evidence pack, and determinism contract. | Execution detail. |
GET /api/iaf/decision-replay/determinism-health | Return determinism health segmented by agent, tower, or autonomy level. | Determinism. |
GET /api/iaf/decision-replay/replay/{execution_id} | Replay stored evidence in historical, shadow, deterministic, current-policy, or scenario mode. | Replay execution. |
GET /api/iaf/decision-replay/evidence-lineage/{execution_id} | Return evidence lineage, agent/policy version history, and lineage integrity. | Evidence replay. |
GET /api/iaf/decision-replay/audit-pack/{execution_id} | Return exportable decision audit pack with execution, replay, lineage, evidence, and contract. | Audit pack. |
GET /api/iaf/decision-replay/execution-deep/{execution_id} | Return deep drill payload for decision, policy, evidence, value, and timeline views. | Technical trace. |
GET /api/iaf/decision-replay/execution-graph/{execution_id} | Return decision-context graph nodes and edges. | Graph replay. |
GET /api/iaf/decision-replay/risk-panel | Return high-risk, escalations, SLA breaches, and override replay posture. | Risk replay. |
GET /api/iaf/decision-replay/chaos-replay/{execution_id} | Run what-if replay with changed tolerance, risk tier, or SOR delay. | Scenario comparison. |
GET /api/iaf/enterprise-decision-runtime/replay/{decision_id} | Return deterministic Decision Runtime replay. | Decision replay. |
GET /api/iaf/enterprise-decision-runtime/replay-live/{decision_id} | Return persisted live replay envelope for a decision. | Live reconstruction. |
GET /api/iaf/enterprise-decision-runtime/replay-live/{decision_id}/compare | Compare persisted decision-time replay with current deterministic replay. | Comparative replay. |
GET /api/iaf/control-plane/replay/{decision_id} | Return role-scoped replay for a decision. | Role projection. |
GET /api/iaf/control-plane/replay/{decision_id}/timeline | Return full policy/evidence/supervision timeline. | Timeline. |
POST /api/iaf/control-plane/evidence/export | Export signed evidence bundle projected to a role. | Signed audit export. |
POST /api/eior/executions/{execution_id}/replay | Replay orchestration plan/execution timeline from EIOR attestations. | Orchestration replay. |
| Artifact | Stored In | Replay Function |
|---|---|---|
ReplayManifest | iaf_replay_manifests | Binds execution, decision, evidence pack, agent, entity, policy version, execution mode, and version bindings. |
ReplayRun | iaf_replay_runs | Stores replay invocation, mode, requested context, status, certification, classification, warnings, and diffs. |
ReplayStep | iaf_replay_steps | Records discrete replay stages such as immutable replay snapshot and runtime boundary checks. |
ReplayDiff | iaf_replay_diffs | Captures differences between original and replayed/current values with severity and category. |
ReplayCertification | iaf_replay_certifications | Records deterministic verification and replay certification result. |
SORStateComparison | iaf_sor_state_comparisons | Stores decision-time versus current source-state hashes and comparison payload. |
| Replay Type | Implemented Source | What It Reconstructs |
|---|---|---|
| Decision replay | Decision Runtime and Decision Replay API | Decision log, outcome, confidence, policy attestation, evidence, approval, telemetry, and replay pointer. |
| Evidence replay | EvidencePack, EvidenceArtifact, signed evidence export | Evidence hashes, artifact lineage, replayable flag, inputs/outputs hashes, and pack metadata. |
| Policy replay | PolicyAttestationRecord, PolicyEvaluationLog, PolicyViolation | Policy set hash, attestation hash, evaluation results, matched conditions, triggered actions, and violations. |
| Agent/tool replay | AgentExecution and ToolInvocation records | Agent identity, task, execution mode, tool names, skills, status, duration, tokens, SOR calls, and decision refs. |
| Skill replay | SkillExecutionRecord and Skill Fabric execution history | Skill run, input/output hashes, evidence hash, status, selection metadata, execution metadata, and replay ID. |
| Orchestration replay | EIOR attestations and Mission ACT workflow records | Plan, execution graph, step states, human waits, cancellations, workflow runs, workflow steps, and evidence hashes. |
| Event replay | Enterprise Event Runtime and Financial Event Fabric | Business event timelines, filtered replay, partial replay, event hashes, and event lineage. |
| Comparative replay | Decision Runtime live compare and SOR state comparison model | Decision-time state versus current deterministic replay or current source-state representation. |
| Role | Included Detail | Restricted Detail |
|---|---|---|
| Analyst | Timeline, artifacts, policy trace, decision status, outcome. | Hashes and governance internals are reduced. |
| Supervisor | Timeline, artifacts, hashes, policy trace, governance, evidence, and outcome. | Only source entitlement restrictions still apply. |
| Auditor | Timeline, hashes, artifacts, policy trace, governance, evidence, signed export. | Sensitive fields remain governed by evidence and identity policies. |
| CFO | Short timeline and summary-level status. | Artifacts, hashes, policy trace, and governance internals are compressed. |
Decision Runtime live replay reconstructs the persisted envelope for a decision and computes an integrity hash over the replay payload.
{
"runtime": "enterprise_decision_runtime",
"found": true,
"decision_log": {
"decision_status": "APPROVAL_REQUIRED",
"outcome": "hold_recommended",
"replay_pointer": "sha256:..."
},
"evidence_pack": {
"evidence_hash": "sha256:...",
"is_replayable": true
},
"policy_attestation": {
"decision": "REQUIRES_HUMAN_APPROVAL",
"attestation_hash": "sha256:..."
},
"replay_manifest": {
"execution_mode": "deterministic_first",
"version_bindings": {"policy_version": "runtime-bound"}
},
"tool_invocations": [
{"tool_name": "sap_read_invoice", "status": "completed", "sor_calls": 1}
],
"integrity_hash": "sha256:..."
}
ReplayManifest, ReplayRun, and ReplayStep records.Any runtime that creates a material recommendation, decision, approval, source-system action, policy attestation, evidence pack, skill result, tool call, or orchestration step must emit enough identifiers, version bindings, hashes, and timestamps for Replay Runtime to reconstruct the event later. If the replay artifact is incomplete, the UI and APIs must say partial replay rather than imply full reconstruction.
The Enterprise Learning Runtime is the governed improvement layer for Sphere. It captures outcomes, feedback, overrides, evidence gaps, policy friction, skill performance, agent quality, and process patterns, then turns them into validated, approved, replay-linked improvement candidates.
The implemented runtime is named Enterprise Memory & Learning Runtime. It combines memory
storage, learning outcomes, learning proposals, governed promotion, semantic retrieval, knowledge graph,
organizational learning, and executive learning observability under one runtime contract.
The runtime is deliberately not uncontrolled AI memory. It can recommend knowledge, policy, skill, routing, workflow, and process improvements, but production behavior changes require validation, review, explicit promotion, versioned metadata, rollback posture, and replayable evidence.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_memory_learning_runtime.py |
Implements Enterprise Memory & Learning Runtime for governed memory, learning outcomes, proposal generation, closed-loop learning, semantic retrieval, knowledge graph, flywheel, executive console, observability, and certification. |
| API surface | /api/emlr/* |
Exposes contract, memory store/search/semantic-search, similar cases, learning outcome, closed-loop learning, proposal generation, learning engine, knowledge graph, personalized insights, flywheel, executive console, certification, forget, promote, and KPIs. |
| Learning records | AgentLearningFeedback, PolicyEffectivenessSnapshot, BehaviorDriftSnapshot, and OrganizationalChangeRecord |
Persists governed feedback, policy effectiveness, behavior drift, and enterprise change candidates with evidence hash, replay reference, owner, approval state, and value-claim boundary. |
| Memory and outcome records | EnterpriseMemoryEntry, CrestLearningOutcome, SkillLearningOverlay, and VNextImpactLearningEntry |
Stores decision memory, learning outcomes, skill overlays, and impact-learning entries that can be searched, reviewed, promoted, graphed, and replay-linked. |
| Promotion governance | learning_promotion_service.py and skill_learning_overlay_runtime.py |
Validates evidence, confidence, target policy, non-contradiction, runtime effect, and approval state before promotion; blocks unvalidated learning from mutating runtime metadata. |
| Feedback contract | learning_feedback_runtime.py and config/contracts/learning_feedback_contract.yaml |
Defines feedback and drift dimensions used to normalize learning payloads and drift records. |
| Tenant learning governance | config/tenants/bp/learning_governance.yaml |
Configures BP staged rollout, dual approval threshold, rollback triggers, evidence outbox emission, retention, actor logging, rationale requirement, and learning evidence contract. |
| Certification | tests/test_enterprise_memory_learning_runtime_certification.py |
Verifies measured certification, closed-loop learning validation, no auto-mutation, governed promotion pipeline, semantic search, knowledge graph, flywheel, executive console, and production gates. |
| Operational surfaces | Enterprise Learning Runtime, Decision Memory, Learning Fabric, Learning Proposals, and Institutional Memory | Users can inspect learning candidates, memory records, replay-backed patterns, promotion posture, and institutional memory. |
CrestLearningOutcome records with decision reference, proposal type, confidence, source payload, evidence hash, proposed status, and promotion reference.Runtime Outcomes / Human Feedback / Replay / Evidence / Policy / Agent / Skill / Workflow
|
v
Learning Signal or Memory Capture
|
v
Enterprise Learning Runtime
|
+-- Memory Store
+-- Learning Outcome Store
+-- Feedback Contract Adapter
+-- Learning Engine
+-- Pattern Clusterer
+-- Proposal Generator
+-- Validation Gate
+-- Promotion Pipeline
+-- Skill Overlay Governance
+-- Policy Metadata Promotion
+-- Knowledge Graph Builder
+-- Semantic Retrieval
+-- Personalized Insight Engine
+-- Executive Learning Console
+-- Observability and Certification
+-- Rollback Governance
|
v
Approved Memory / Learning Proposal / Skill Overlay / Policy Candidate / Organizational Change Record / Learning Metrics
CrestLearningOutcome proposal.| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/emlr/contract | Return runtime scope, memory/knowledge boundary, APIs, governance, promotion pipeline, and certification posture. | Runtime definition. |
POST /api/emlr/memory/store | Store governed memory with mission, domain, decision, policy, evidence, classification, trust, tags, and metadata. | Memory capture. |
GET /api/emlr/memory/search | Search enterprise memory using semantic-keyword hybrid retrieval. | Memory retrieval. |
GET /api/emlr/memory/semantic-search | Run local 256-dim hash-embedding memory retrieval (pgvector-swappable; no external vector DB required yet). | Semantic retrieval. |
GET /api/emlr/cases/{case_id}/similar | Find similar cases from memory entries and memory episodes. | Case reuse. |
POST /api/emlr/learning/outcome | Create proposed learning outcome and optional agent learning feedback. | Signal capture. |
POST /api/emlr/learning/closed-loop | Create, validate, optionally promote, and report closed-loop learning with promotion pipeline state. | Closed-loop learning. |
POST /api/emlr/learning/proposals | Generate learning proposals from decision observations and detected clusters. | Candidate generation. |
POST /api/emlr/learning/engine | Run deterministic pattern, trend, cluster, and lesson synthesis. | Pattern detection. |
GET /api/emlr/knowledge-graph | Materialize memory, mission, domain, entity, policy, and decision nodes/edges. | Knowledge graph. |
POST /api/emlr/personalized-insights | Return role-specific memory recommendations for analyst, supervisor, controller, CFO, auditor, developer, or executive roles. | Personalization. |
GET /api/emlr/flywheel | Return enterprise intelligence flywheel inputs, learning conversion, outputs, cross-mission reuse, and graph summary. | Learning flywheel. |
GET /api/emlr/executive-console | Return learning maturity, recurring issues, policy candidates, automation opportunities, and self-improvement queue. | Executive learning console. |
GET /api/emlr/observability-contract | Return metrics, alerts, dashboards, and runbooks for memory and learning operations. | Observability. |
GET /api/emlr/production-certification | Run production gates for memory, closed-loop learning, promotion pipeline, flywheel, graph, personalization, and observability. | Release gate. |
POST /api/emlr/memory/{memory_id}/forget | Retire a memory record with actor and reason. | Memory governance. |
POST /api/emlr/memory/{memory_id}/promote | Promote memory to approved, certified enterprise memory with promotion hash. | Memory promotion. |
POST /api/iaf/decision-intelligence/skill-learning-overlays/{overlay_id}/validate | Validate a skill learning overlay before promotion. | Skill learning gate. |
POST /api/iaf/decision-intelligence/skill-learning-overlays/{overlay_id}/promote | Promote an approved skill learning overlay into runtime metadata. | Skill learning promotion. |
POST /api/iaf/skills/overlays | Create a proposed Skill Fabric learning overlay. | Overlay proposal. |
GET /api/iaf/skills/overlays | List skill learning overlays by skill or status. | Overlay registry. |
POST /api/iaf/skills/overlays/{overlay_id}/review | Approve, reject, or retire a skill learning overlay. | Overlay review. |
POST /api/enterprise-cognitive-os/learning-signal | Qualify a learning signal from decision artifact and outcome. | Cognitive OS signal. |
POST /crest/learning/propose | Create a CREST learning outcome proposal. | CREST learning proposal. |
POST /crest/learning/{outcome_id}/review | Update CREST learning outcome review state. | CREST review. |
GET /crest/learning/outcomes | List CREST learning outcomes by mission and status. | Learning outcome registry. |
| Artifact | Stored In | Runtime Function |
|---|---|---|
EnterpriseMemoryEntry | iaf_enterprise_memory_entries | Governed memory with content hash, trust, approval, classification, policy/evidence/decision references, and lifecycle. |
CrestLearningOutcome | iaf_crest_learning_outcomes | Learning outcome proposal with type, confidence, payload, status, reviewer, and promotion reference. |
AgentLearningFeedback | iaf_agent_learning_feedback | Agent feedback linked to decision/execution, policy, outcome value, feedback source, payload, and evidence hash. |
SkillLearningOverlay | iaf_skill_learning_overlays | Skill-targeted learning overlay with proposed payload, confidence, review state, validation, and promotion binding. |
PolicyEffectivenessSnapshot | iaf_policy_effectiveness_snapshots | Policy learning measurement with sample count, success rate, override rate, value, and improvement signals. |
BehaviorDriftSnapshot | iaf_behavior_drift_snapshots | Agent/policy behavior drift score, baseline/current window, indicators, and recommended action. |
OrganizationalChangeRecord | iaf_organizational_change_records | Append-only enterprise change ledger for approved learning promotions and replay/evidence-backed change candidates. |
| Stage | Implemented Gate | Production Boundary |
|---|---|---|
candidate_learning_identified | Learning engine or outcome API creates candidate. | No runtime behavior changes. |
expert_review | Validated when confidence or explicit validation supports review. | Human review remains required. |
business_validation | Requires evidence of frequency, value, or measured outcome. | Learning remains advisory. |
policy_validation | Promotion service validates target policy, evidence, confidence, and non-contradiction. | Inactive/retired policy targets block promotion. |
pilot_deployment | Only complete after explicit promotion request and validation pass. | Staged rollout governed by tenant config. |
outcome_measurement | Measures value, accuracy, sample count, override rate, and policy effectiveness. | Regression can trigger rollback. |
enterprise_rollout | Allowed only after promotion and sufficient confidence. | Promotion updates metadata, not uncontrolled model state. |
continuous_monitoring | Executive console, KPIs, observability, and governance config monitor impact. | Rollback remains available. |
| Signal Type | Implemented Source | Allowed Runtime Effect |
|---|---|---|
| Human feedback | AgentLearningFeedback, Agent Runtime learning feedback, EMLR outcome payload. | Guidance, memory, candidate proposal, or owner review queue. |
| Evidence gap | Evidence hash absence, source cases, memory metadata, learning engine clusters. | Evidence profile or workflow improvement candidate. |
| Policy friction | Policy ID clustering, policy effectiveness snapshots, override rate, repeated proposals. | Policy metadata candidate or policy-owner review item. |
| Skill quality | Skill learning overlays and skill execution/replay metadata. | Validated overlay metadata, threshold/routing/test-case candidate. |
| Agent quality | Agent feedback, recommendation outcomes, before/after accuracy, evidence references. | Agent guidance or planning adjustment candidate. |
| Workflow bottleneck | Learning engine clusters over workflow observations and memory episodes. | Workflow optimization candidate, not direct mission graph mutation. |
| Value realization | Outcome value, policy effectiveness, organizational change records, value event linkage. | Impact learning and business case for promotion. |
| Control | BP Configuration | Runtime Effect |
|---|---|---|
| Approval | Default owner bucket ops_lead; dual approval above impact score 0.50. | Behavior-changing learning routes through owners. |
| Staged rollout | shadow, 10pct, 50pct, 100pct cohorts with KPI guardrails. | Promotions do not jump directly to full estate. |
| Rollback | KPI drift threshold, high drift alert, or operator initiation. | Reverts to prior calibration and notifies configured roles. |
| Evidence | Outbox subject prefix iris.bp.learning and 365-day retention. | Learning changes are evidence-emitting and retained. |
| Audit | Actor logging and rationale required with evidence contract contract.learning.bp.v1. | Every applied learning action is attributable. |
A repeated duplicate-invoice evidence pattern can become a learning outcome. The runtime validates it, blocks automatic mutation, and exposes the promotion pipeline state for owner review.
{
"operation": "ClosedLoopLearning",
"learning": {
"status": "proposed",
"promotion_allowed_without_approval": false,
"governance": "proposed_learning_requires_review_before_runtime_effect"
},
"validation": {
"passed": true,
"checks": {
"has_evidence": true,
"has_target_policy": true,
"confidence_above_floor": true,
"non_contradiction": true
}
},
"promotion": {
"attempted": false,
"promoted": false
},
"closed_loop": {
"outcome_measured": true,
"business_success_measured": true,
"auto_mutation_blocked": true
}
}
auto_mutation_blocked=true and promotion_allowed_without_approval=false.Do not implement learning as free-form conversation memory or automatic self-modification. Capture structured signals, bind evidence and replay references, validate quality, classify the target artifact, route review, promote through an explicit gate, and measure post-promotion impact with rollback available.
The Enterprise Observability Runtime is the operational intelligence layer for Sphere. It collects, correlates, persists, analyzes, and reports telemetry across platform runtimes, agents, skills, policies, evidence, decisions, business processes, security events, model usage, cost, and value.
Observability is not only log capture. The implemented runtime defines a unified telemetry model that combines technical metrics, AI/model signals, policy and evidence checkpoints, security events, cost, business impact, replay references, and operational health.
The runtime does not execute business decisions or automatically repair production behavior. It exposes health, traceability, alerts, diagnostics, and recommendation packets. Remediation remains recommend-only until policy and owner approval are captured.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_observability_runtime.py |
Implements cross-runtime operational, business, AI, policy, evidence, security, performance, value, alerting, remediation, governance, OpenTelemetry, and executive operations observability. |
| API surface | /api/eor/* |
Exposes contract, telemetry model, telemetry ingest, durable telemetry, persisted telemetry hydration, runtime health, distributed trace, drilldown, domain observability views, alerts, remediation, governance, integrations, and certification. |
| Durable telemetry store | RuntimePerformanceTelemetry / iaf_runtime_performance_telemetry |
Persists page/persona/mission/case/action latency, token count, model, SAP calls, cache hit, decision ID, evidence pack ID, outcome, error code, metadata JSON, realm, and timestamp. |
| Unified telemetry contract | UNIFIED_TELEMETRY_FIELDS |
Requires runtime, mission, process, business entity, correlation ID, user/agent ID, policy reference, evidence reference, decision reference, cost, business impact, and timestamp. |
| Trace model | distributed_trace() and drilldown_packet() |
Correlates spans by correlation ID and returns policy checkpoints, evidence checkpoints, replay identifiers, bottlenecks, executive summary, governance references, and source lineage. |
| OpenTelemetry bridge | open_telemetry_contract() |
Maps runtime telemetry to resource attributes, span attributes, histogram/counter/gauge metrics, OTLP, Prometheus, structured logs, and W3C trace context. |
| FinOps integration | finops_runtime.py |
Builds ledger-first AI economics from LLM audit, agent execution, value events, mission budgets, token intelligence, model routing, SAP call intelligence, cache intelligence, and cost-per-decision envelopes. |
| Alerting assets | ops/observability/eor_rules.yaml |
Defines health, trace coverage, business value telemetry, governance checkpoint coverage, and operational-risk alerts. |
| Dashboard asset | ops/observability/eor_executive_operations_dashboard.json |
Defines executive panels for platform health, runtime health scores, business value, AI utilization, policy compliance, and operational risk. |
| Certification | tests/test_enterprise_observability_runtime_certification.py |
Verifies no fake health, live telemetry measurement, hash-backed telemetry, durable persistence, trace correlation, OpenTelemetry mapping, remediation governance, alerts, command center, and production gates. |
| Operational surfaces | Runtime Command Center, Enterprise Observability Runtime, FinOps Command Center, and Platform Observability | Users can inspect runtime health, agent quality, cost, traceability, readiness, incidents, and operational proof surfaces. |
no_samples when no telemetry has been captured.All Sphere Runtimes / Agents / Skills / UI / Integrations / Models
|
v
Unified Telemetry Record
|
v
Enterprise Observability Runtime
|
+-- Unified Telemetry Model
+-- Runtime Health Scorer
+-- Distributed Trace Correlator
+-- Drilldown Packet Builder
+-- Business Process Observability
+-- AI Observability
+-- Policy Observability
+-- Evidence Observability
+-- Security Observability
+-- Performance Analytics
+-- Business Value Analytics
+-- Alerting and Incident Management
+-- Governed Remediation Recommendations
+-- OpenTelemetry Mapping
+-- Durable Telemetry Store
+-- Executive Operations Command Center
|
v
Runtime Health / Trace / Alert / Drilldown / Cost / Value / Governance / Certification
/api/eor/telemetry or persisted through /api/eor/telemetry-durable.RuntimePerformanceTelemetry with correlation, trace, policy, evidence, replay, cost, business impact, and telemetry hash metadata./api/eor/load-persisted-telemetry without fabricating runtime samples.| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/eor/contract | Return runtime scope, ownership, observed runtimes, telemetry domains, fields, differentiators, and production boundaries. | Runtime definition. |
GET /api/eor/telemetry-model | Return required and optional telemetry fields, correlation model, and governance requirements. | Schema contract. |
POST /api/eor/telemetry | Record in-memory unified telemetry and evaluate alert thresholds. | Telemetry ingest. |
POST /api/eor/telemetry-durable | Record telemetry and persist it to RuntimePerformanceTelemetry. | Durable ingest. |
POST /api/eor/load-persisted-telemetry | Hydrate runtime state from persisted telemetry records. | Durable replay. |
GET /api/eor/runtime-health | Return per-runtime health, availability, latency, error rate, throughput, cost, readiness, and sample status. | Health scoring. |
GET /api/eor/trace/{correlation_id} | Return distributed trace, spans, parent-child relationships, policy/evidence checkpoints, replay identifiers, and bottlenecks. | Trace correlation. |
GET /api/eor/drilldown/{correlation_id} | Return executive summary, governance refs, bottlenecks, and source lineage for a trace. | Root-cause packet. |
GET /api/eor/business-processes | Return throughput, SLA, automation, business value, exception rate, and cycle time by process. | Business telemetry. |
GET /api/eor/ai | Return model usage, tokens, cost, human intervention rate, confidence, and AI quality trend. | AI telemetry. |
GET /api/eor/policy | Return policy evaluation count, failure count, failure rate, latency, and compliance score. | Policy telemetry. |
GET /api/eor/evidence | Return evidence count, completeness, missing evidence, replay readiness, audit readiness, and quality trend. | Evidence telemetry. |
GET /api/eor/security | Return security events by type and security posture. | Security telemetry. |
GET /api/eor/performance | Return latency, queue utilization, cache efficiency, cost efficiency, and scalability signal. | Performance analytics. |
GET /api/eor/business-value | Return financial impact, runtime cost, ROI, automation rate, risk reduction, and decision quality. | Value analytics. |
GET /api/eor/alerts-incidents | Return alert and incident workflows, thresholds, incidents, and alert inventory. | Alerting. |
GET /api/eor/remediation-recommendations | Return governed remediation recommendations and approval requirements. | Remediation. |
GET /api/eor/executive-command-center | Return enterprise health, AI utilization, value, automation, policy compliance, risk, cost, adoption, and security posture. | Executive ops. |
POST /api/eor/emit-runtime-metrics | Invoke the runtime metrics emitter and record the emission as observability telemetry. | Metric emission. |
GET /api/eor/governance | Return ownership, retention, access control, classification, audit logging, and remediation governance. | Governance. |
GET /api/eor/opentelemetry-contract | Return OpenTelemetry resource attributes, span attributes, metric types, exporters, and trace context. | OTel contract. |
GET /api/eor/integrations | Return supported integrations for OpenTelemetry, Prometheus, Grafana, Jaeger, Loki, Kubernetes, SAP, Databricks, Teams, ServiceNow, Azure Monitor, and CloudWatch. | Ops integration. |
GET /api/eor/world-class-certification | Return measured certification based on telemetry coverage and operational visibility. | Certification. |
GET /api/eor/production-certification | Return production gates for schema, trace, health, domain views, alerting, governance, durable store, OpenTelemetry, remediation, and drilldown. | Release gate. |
| Field | Purpose | Required Boundary |
|---|---|---|
runtime_id | Identifies the runtime that emitted the telemetry. | All records. |
mission, process, business_entity | Connects telemetry to business operations. | Business-aware observability. |
correlation_id, trace_id | Links spans into a distributed trace. | Trace correlation. |
user_agent_id | Identifies user, system, or agent actor. | Accountability. |
policy_ref, evidence_ref, decision_ref, replay_id | Links telemetry to governance artifacts. | Control and replay. |
cost_usd, business_impact_usd | Connects runtime work to cost and value. | FinOps and value analytics. |
latency_ms, error_count, sla_target_ms, status | Supports health, SLO, alerting, and degraded-mode views. | Operations. |
tokens, model, tool_name, confidence | Supports AI and agent quality telemetry. | AI operations. |
evidence_completeness, policy_status, security_event | Supports evidence, policy, and security observability. | Governance. |
| Runtime | Health Basis | Primary Signals |
|---|---|---|
| Policy Intelligence | Telemetry samples for enterprise_policy_intelligence_runtime. | Policy failures, latency, compliance, security events. |
| Decision | Telemetry samples for enterprise_decision_runtime. | Decision latency, value, confidence, policy/evidence references. |
| Context | Telemetry samples for enterprise_context_runtime. | Context latency, cache, dependencies, trace coverage. |
| Evidence | Telemetry samples for evidence_intelligence_runtime. | Evidence completeness, replay readiness, audit readiness. |
| Learning | Telemetry samples for enterprise_memory_learning_runtime. | Learning health, value, governance, process signals. |
| Event | Telemetry samples for enterprise_event_runtime. | Event throughput, failure rate, correlation state. |
| Agent | Telemetry samples for enterprise_agent_runtime. | Model, tokens, tool, confidence, cost, intervention rate. |
| Skill | Telemetry samples for enterprise_skill_runtime. | Skill latency, cost, confidence, tool dependency. |
| Knowledge | Telemetry samples for enterprise_knowledge_runtime. | Knowledge trace, retrieval, quality, governance refs. |
| Integration | Telemetry samples for enterprise_integration_runtime. | Integration latency, SAP/Databricks dependencies, errors. |
| Assurance | Telemetry samples for enterprise_assurance_runtime. | Control assurance, evidence, replay, audit posture. |
| Alert | Condition | Operational Meaning |
|---|---|---|
EORRuntimeHealthBelowThreshold | Runtime health score below readiness threshold. | Runtime estate is degraded. |
EORTraceCoverageDropped | Cross-runtime trace coverage below audit threshold. | Root-cause and replay linkage are at risk. |
EORBusinessValueTelemetryMissing | No business value telemetry in observability records. | Platform value cannot be substantiated. |
EORPolicyEvidenceCheckpointMissing | Policy or evidence checkpoints missing from traces. | Governance trace completeness is below threshold. |
EOROperationalRiskElevated | Open incident count above zero. | Operational risk requires attention. |
A duplicate-invoice decision path can emit a single unified record that ties operational telemetry to governance artifacts, cost, and business impact.
{
"runtime_id": "enterprise_decision_runtime",
"mission": "p2p",
"process": "duplicate_invoice_resolution",
"business_entity": "invoice",
"correlation_id": "corr-eor-001",
"user_agent_id": "duplicate_invoice_agent",
"policy_ref": "duplicate_payment_control",
"evidence_ref": "evidence-pack-eor-001",
"decision_ref": "decision-eor-001",
"cost_usd": 0.02,
"business_impact_usd": 125000,
"latency_ms": 420,
"tokens": 1300,
"model": "governed-model",
"tool_name": "duplicate_invoice_detection",
"confidence": 0.95,
"evidence_completeness": 1.0,
"replay_id": "replay-eor-001",
"status": "completed"
}
no_samples instead of fabricated green status.telemetry_hash and can carry cost, business impact, policy, evidence, decision, replay, and trace references.RuntimePerformanceTelemetry and reloadable into the runtime.Do not reduce observability to application logs. Every material runtime action should emit structured telemetry with correlation, governance references, latency, status, cost, business impact, and replay linkage where available. If the telemetry is missing, the system must show an explicit gap rather than imply healthy operation.
The Enterprise Integration Runtime is the governed connectivity layer for Sphere. It standardizes how runtimes, agents, skills, and workflows discover connectors, read business objects, enforce security, preserve source lineage, register mappings, record connector health, and produce replayable integration traces.
The runtime prevents direct, unmanaged source-system access. Business-object reads go through Enterprise Security Runtime and DataAccessGateway, and each successful read can be persisted as an integration trace. The current implementation is strongest on governed read access, connector catalog, mapping registry, connector health, source-status classification, and integration traceability.
Write-back is represented as a governed boundary and connector contract, not as unrestricted execution. SAP and ServiceNow write-capable paths are intentionally described as contract or dry-run boundaries until policy, decision, human approval, production adapter, credential, and tenant controls authorize real writes.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_integration_runtime.py |
Implements the governed connectivity facade over DataAccessGateway, security gateway, connector catalog, integration contracts, mapping registry, health history, durable traces, and executive integration console. |
| API surface | /api/integrations/* |
Exposes contract, connectors, fabric, API management, transformation, synchronization, governance, error handling, security, AI integration, data governance, observability, marketplace, mappings, connector health, business-object reads, trace search, executive console, runtime interoperability, and certification. |
| Connector catalog | connector_catalog() |
Combines finance KDO read-model connectors with governed platform connector contracts for SAP S/4HANA, SAP Ariba, Databricks Unity Catalog, Microsoft Graph 365, ServiceNow, OpenAI, Anthropic, Ollama Local, and Kafka/NATS event mesh. |
| Connectivity fabric | connectivity_fabric() |
Defines the standard connector contract: security-runtime authentication, standard error envelope, bounded retry with circuit breaker, source lineage/evidence reference, runtime telemetry, policy-before-sensitive-action, and replay support through correlation ID and trace hash. |
| Governed read path | read_business_object() |
Routes reads through Enterprise Security Runtime and DataAccessGateway, then persists a durable integration trace with connector, source status, provenance, policy reference, evidence reference, security decision, record count, and trace hash. |
| Durable traceability | IntegrationAuditTrace / iaf_integration_audit_traces |
Stores trace ID, connector, business object, action, success, source status, provenance, record count, latency, policy/evidence/security refs, trace hash, metadata, realm, and timestamp. |
| Mapping registry | IntegrationMappingDefinition / iaf_integration_mapping_definitions |
Persists governed transformation mappings by source system, target system, business object, mapping type, version, owner, status, and definition JSON. |
| Connector health | IntegrationConnectorHealth / iaf_integration_connector_health |
Stores connector status, source status, latency, error count, freshness status, metadata, realm, and checked timestamp for health history. |
| Security and AI boundaries | security_contract() and ai_integration() |
Declares authentication, authorization, OAuth/SAML/API key/mTLS/certificate/secret controls, audit logging, model abstraction, provider failover, cost optimization, token tracking, and sovereign AI support. |
| Certification | tests/test_enterprise_integration_runtime_certification.py |
Verifies connector catalog, standardized fabric, no direct agent external access, policy enforcement, replay support, MCP API style, mapping registry, health history, durable traces, source-status classification, and production gates. |
| Operational surfaces | Data Trust Explorer, Capability Readiness Center, Integration Adapter Library, and Data Integrations | Users can inspect source trust, integration readiness, adapter patterns, connector posture, and integration dependencies. |
read_model, live, test-double, local, contract, blocked, unavailable, and unknown source states.IntegrationAuditTrace with replayable trace hashes and governance references.Context / Evidence / Agent / Skill / Decision / Orchestration Runtime
|
v
Integration Request
|
v
Enterprise Integration Runtime
|
+-- Connector Catalog
+-- Enterprise Connectivity Fabric
+-- Security Runtime Gateway
+-- DataAccessGateway Adapter
+-- Business Object Reader
+-- Source Status Classifier
+-- Transformation Contract
+-- Synchronization Contract
+-- Error Handling Contract
+-- Integration Mapping Registry
+-- Connector Health History
+-- Integration Audit Trace
+-- Marketplace
+-- Executive Integration Console
+-- Production Certification
|
v
Read Model / Live Connector / Test Connector / Local Connector / Contract Connector / Event Mesh / AI Provider
| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/integrations/contract | Return runtime scope, owned capabilities, non-owned boundaries, business objects, backing services, and differentiators. | Runtime definition. |
GET /api/integrations/connectors | Return standardized connector catalog with categories, source statuses, access modes, certification status, and business objects. | Connector registry. |
GET /api/integrations/fabric | Return standard connector contract, direct-access prohibition, replay support, policy enforcement, health model, and supported patterns. | Connectivity fabric. |
GET /api/integrations/api-management | Return supported API styles, versioning, documentation, rate limiting, gateway, analytics, and lifecycle management. | API management. |
GET /api/integrations/transformation | Return schema/field mapping, normalization, validation, conversion, enrichment, preservation, AI-assisted mapping, and registry contract. | Transformation. |
GET /api/integrations/synchronization | Return sync patterns, conflict detection, retry sync, offline sync, and governed bidirectional sync contract. | Synchronization. |
GET /api/integrations/governance | Return required ownership fields, governance board checks, and integration readiness certification scores. | Governance. |
GET /api/integrations/error-handling | Return retry, circuit breaker, dead-letter, timeout, duplicate detection, compensation, recovery, and error categorization contract. | Resilience. |
GET /api/integrations/security | Return authentication, authorization, OAuth, SAML, API key, mTLS, certificate, encryption, secrets, audit, and security gateway posture. | Security. |
GET /api/integrations/ai | Return model abstraction, multi-model routing, provider failover, cost/latency optimization, prompt routing, tools, streaming, health, token tracking, and sovereign AI support. | AI integration. |
GET /api/integrations/data-governance | Return lineage, ownership, quality, masking, privacy, retention, compliance, residency, master-data consistency, and auditability. | Data governance. |
GET /api/integrations/observability | Return API health, connector health, throughput, latency, error-rate model, retry activity, sync, cost, runtime health, SLA, and health-history source. | Observability. |
GET /api/integrations/marketplace | Return connector discovery, API discovery, certification, version history, usage analytics, dependencies, owner, SLA, docs, and catalog. | Marketplace. |
POST /api/integrations/mappings | Register an integration mapping definition. | Mapping registry. |
GET /api/integrations/mappings/search | Search mapping definitions by business object. | Mapping lookup. |
POST /api/integrations/health | Persist connector health record. | Health history. |
GET /api/integrations/health/search | Search connector health records. | Health lookup. |
POST /api/integrations/business-object/read | Read a canonical business object through security and data-access gateway. | Governed read. |
GET /api/integrations/business-object/read | Read a canonical business object through query parameters. | Governed read. |
GET /api/integrations/traces/search | Search persisted integration audit traces by connector or business object. | Replay and audit. |
GET /api/integrations/executive-console | Return integration health, connector utilization, freshness, synchronization, cost, business impact, SLA, maturity, and traceability posture. | Executive operations. |
GET /api/integrations/runtime-interoperability | Return runtimes that must use Integration Runtime for external system access. | Runtime boundary. |
GET /api/integrations/world-class-certification | Return measured connector liveness/governance certification and connector provenance. | Certification. |
GET /api/integrations/production-certification | Return production gates for integration architecture, security, governance, marketplace, durable traceability, mappings, health, and source status. | Release gate. |
| Status | Meaning | Operational Rule |
|---|---|---|
read_model | Local or ingested read model populated by source-system ingestion. | Allowed for governed reads with disclosed provenance. |
live | Live external connector credentials and endpoint are available. | Allowed according to connector policy and role. |
test_double | Test connector mode, such as Microsoft Graph test mode. | Must be labeled as test-only and not treated as production source truth. |
local | Local runtime connector such as sovereign local model provider. | Allowed within local runtime policy. |
contract | Governed connector contract exists, but production endpoint is not asserted live. | Valid architecture boundary; not a live-data claim. |
blocked_until_credentials | Connector requires credentials before live use. | Do not execute; expose dependency. |
unavailable | Source path unavailable. | Return safe failure and preserve trace. |
| Artifact | Stored In | Runtime Function |
|---|---|---|
IntegrationAuditTrace | iaf_integration_audit_traces | Replayable trace of connector, object, action, success, source status, provenance, policy/evidence/security refs, hash, and metadata. |
IntegrationMappingDefinition | iaf_integration_mapping_definitions | Versioned mapping registry for source-to-target business-object transformations. |
IntegrationConnectorHealth | iaf_integration_connector_health | Connector health history for status, source status, latency, errors, freshness, and operational reporting. |
A Context or Evidence Runtime request for invoice data is routed through security, DataAccessGateway, the standard fabric contract, and durable integration trace persistence.
{
"operation": "ReadBusinessObject",
"allowed": true,
"business_object": "invoice",
"gateway_result": {
"kdo": "kdo://finance/invoice",
"access_path": "mcp_ihub_gateway",
"connector": "external_sor",
"provenance": "live_read_model",
"record_count": 2
},
"standard_fabric": {
"authentication_model": "security_runtime_gateway",
"policy_enforcement": "policy_runtime_before_sensitive_action",
"replay_support": "correlation_id_and_trace_hash"
},
"durable_trace": {
"stored": true,
"model": "IntegrationAuditTrace",
"trace_id": "eir-000001"
}
}
Do not let agents, skills, pages, or workflows call enterprise systems directly. They should request integration through the runtime, which applies security, discloses source status, preserves lineage, records traces, and keeps write-capable behavior behind explicit policy, decision, approval, and adapter gates.
The Enterprise Identity, Security & Trust Runtime is implemented as
enterprise_security_runtime. It is the security gateway for Sphere: every human, agent,
service, connector, workflow, API, tool, and model must operate under explicit identity, least privilege,
adaptive trust, data protection, AI-specific controls, and replayable security audit.
The runtime centralizes security enforcement for the rest of the platform. Policy, decision, agent, context, evidence, memory, knowledge, event, integration, and assurance runtimes can call the mandatory security gateway before sensitive data access, privileged action, tool use, write-like behavior, external sharing, or AI interaction.
The current implementation owns Sphere-specific authorization, zero-trust scoring, tool permission checks, AI and agent protection, data-protection contracts, secret-provider contracts, durable security audit, and provider readiness. It does not replace Entra ID, SAML/OIDC providers, PAM, SIEM, DLP, network controls, or source-system authorization; it consumes or integrates with those controls where configured.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime service | enterprise_security.py |
Implements the identity-first security runtime for humans, agents, tools, models, APIs, services, workflows, connectors, and background jobs. |
| Runtime identity | enterprise_security_runtime |
Registered in runtime certification as priority 12 with module iris_sor.services.enterprise_security, API prefix /api/security, UI routes /ui/access-controls and /ui/security, and durable entity SecurityAuditEvent. |
| API surface | /api/security/* |
Exposes contract, identity registry, authentication contract, authorization, zero-trust evaluation, AI protection, agent action evaluation, secrets, data protection, API security, infrastructure security, events, durable events, event search, gateway evaluation, forwarding contract, provider readiness, threats, incidents, compliance, observability, integrations, executive command center, governance, and certification. |
| Identity registry | identity_registry() |
Declares first-class human identities and machine identities: employee, contractor, vendor, auditor, executive, administrator, agent, skill, API, service, workflow, event producer, event consumer, background job, connector, and AI model. |
| Authentication contract | authentication_contract() |
Declares SSO, SAML, OAuth, OpenID Connect, Entra ID, MFA, passwordless sessions, workload identity, certificate authentication, API keys with rotation, service accounts, model identity, continuous revalidation, MFA for privileged actions, step-up for sensitive data, and session risk scoring. |
| Authorization engine | authorize() |
Combines role, ABAC sensitivity rules, policy reference, tool permissions, emergency access, field-level permission flagging, masking requirement, and audit requirement into one security decision. |
| Zero-trust evaluation | evaluate_zero_trust() |
Combines authorization, adaptive trust score, device trust, network trust, session age, least privilege, continuous verification, conditional access, and session revalidation requirement. |
| AI and agent protection | protect_ai_interaction() and evaluate_agent_action() |
Detects prompt injection, context poisoning, sensitive leakage risk, unsafe tool execution risk, autonomy boundary issues, write/external action risk, and records high-severity security events when blocked. |
| Mandatory gateway | security_gateway() |
Provides the pre-action gateway for policy, decision, agent, context, evidence, memory, knowledge, event, integration, and assurance runtimes. |
| Durable ledger | SecurityAuditEvent / iaf_security_audit_events |
Persists event ID, event type, severity, subject, runtime, policy/decision/evidence references, integrity hash, forwarding targets, forwarding status, details JSON, realm, and timestamp. |
| Provider readiness | provider_readiness() |
Reports deployment readiness for Entra ID, SAML, OIDC, Microsoft Graph 365 read adapter, Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, and SIEM/SOAR forwarding contracts. |
| Certification | tests/test_enterprise_security_runtime_certification.py |
Verifies runtime scope, identity/authn/authz/zero-trust controls, AI and agent gates, data protection, secrets, API security, durable audit events, provider readiness, API registration, runtime certification registration, production gates, and non-authoritative world-class score reporting. |
User / Agent / Service / Runtime / Connector / Tool / Model
|
v
Identity and Trust Request
|
v
Enterprise Identity, Security & Trust Runtime
|
+-- Identity Registry
+-- Authentication Contract
+-- RBAC / ABAC Authorization Engine
+-- Agent Tool Permission Scope
+-- Adaptive Trust Score
+-- Zero Trust Evaluation
+-- AI Security Protection
+-- Agent Security Gate
+-- Data Protection Contract
+-- Secrets Management Contract
+-- Mandatory Security Gateway
+-- SecurityAuditEvent Ledger
+-- SIEM / SOAR Forwarding Contract
+-- Provider Readiness
+-- Executive Security Command Center
|
v
allow / block_or_step_up / allow_with_masking / audit / incident / provider_gap
SecurityAuditEvent with integrity hash and forwarding state.| Endpoint | Purpose | Runtime Boundary |
|---|---|---|
GET /api/security/contract | Return runtime mission, owned capabilities, non-owned boundaries, identity types, control families, differentiators, and consumed-by runtimes. | Runtime definition. |
GET /api/security/identity-registry | Return human and machine identity categories plus first-class identity requirements. | Identity registry. |
GET /api/security/authentication-contract | Return human and machine authentication methods plus session controls. | Authentication. |
POST /api/security/authorize | Evaluate role, ABAC sensitivity, agent tool permissions, emergency access, masking requirement, policy reference, and audit requirement. | Authorization. |
POST /api/security/zero-trust/evaluate | Evaluate adaptive risk, authorization, device trust, network trust, session age, least privilege, conditional access, and revalidation. | Zero trust. |
POST /api/security/ai/protect | Evaluate prompt injection, context poisoning, sensitive leakage, unsafe tool execution, and model abuse controls. | AI security. |
POST /api/security/agents/evaluate-action | Evaluate agent action against AI security, zero trust, autonomy, external action, human approval, tool restriction, memory protection, and audit logging. | Agent authority. |
GET /api/security/secrets | Return secret-provider and plaintext-storage controls. | Secrets. |
GET /api/security/data-protection | Return encryption, tokenization, masking, pseudonymization, PII detection, residency, retention, and deletion controls. | Data protection. |
GET /api/security/api-security | Return protected API types, rate limiting, gateway, validation, monitoring, and MCP endpoint controls. | API security. |
GET /api/security/infrastructure-security | Return Kubernetes, container, database, storage, network, service mesh, CI/CD, build, and deployment security controls. | Infrastructure contract. |
POST /api/security/events | Register an in-memory security event. | Security event capture. |
POST /api/security/events/durable | Persist a security event to SecurityAuditEvent. | Durable ledger. |
GET /api/security/events/search | Search persisted security events by severity, type, and limit. | Security replay. |
POST /api/security/gateway/evaluate | Run the mandatory security gateway for other runtimes. | Pre-action gateway. |
GET /api/security/forwarding-contract | Return Sentinel, Splunk, and ServiceNow Security Operations forwarding targets and payload contract. | Security operations. |
GET /api/security/provider-readiness | Return identity, graph, secrets, and SIEM/SOAR provider readiness. | Deployment readiness. |
GET /api/security/threats | Return threat counters and security events. | Threat detection. |
GET /api/security/incidents | Return incident response posture and open incidents created from high or critical events. | Incident response. |
GET /api/security/compliance | Return SOX, ISO 27001, SOC 2, GDPR, NIST, CIS, PCI where applicable, internal standards, and AI governance posture. | Compliance. |
GET /api/security/observability | Return authorization failures, threats, incidents, prompt attacks, API abuse, risk score availability, compliance posture, and runtime health. | Security observability. |
GET /api/security/integrations | Return identity, secrets, SIEM, Sentinel, Splunk, SAP identity services, ServiceNow security operations, and forwarding integration posture. | Security integrations. |
GET /api/security/executive-command-center | Return security posture, score, threat landscape, compliance, AI security score, identity health, incident trends, and business impact. | Executive security. |
GET /api/security/governance | Return control ownership, risk classification, review cadence, approval workflows, policy mapping, exception management, audit trails, durable ledger, mandatory gateway, forwarding contract, and readiness scores. | Governance. |
GET /api/security/world-class-certification | Return non-authoritative measured certification until backed by persisted security evidence. | Certification. |
GET /api/security/production-certification | Return release gate results across identity, authentication, authorization, zero trust, secrets, data protection, AI protection, agent gate, API security, compliance, observability, gateway, forwarding, and provider readiness. | Release gate. |
| Decision | Meaning | Implemented Signal |
|---|---|---|
allow | Action or access is permitted. | authorize().allowed=true and security_gateway().decision=allow. |
block_or_step_up | Action is blocked or requires stronger control before proceeding. | Returned by gateway when authorization, trust, AI, or agent gate fails. |
allow_with_masking | Access can continue but sensitive data must be masked. | Represented by data_masking_required=true for restricted or PII-like sensitivity. |
audit | Decision must be ledgered. | audit_required=true and optional durable event persistence. |
incident | High or critical security event creates an incident record. | register_security_event() opens incidents for high or critical severity. |
provider_gap | Provider contract exists but deployment binding is not configured. | provider_readiness() discloses configured versus contract-only status. |
| Artifact | Stored In | Runtime Function |
|---|---|---|
SecurityAuditEvent | iaf_security_audit_events | Append-only security event ledger with event type, severity, subject, runtime, policy, decision, evidence, hash, forwarding, details, realm, and timestamp. |
integrity_hash | SecurityAuditEvent.integrity_hash | SHA-256 hash of the recorded security event payload for tamper-evident replay. |
forwarding_status | SecurityAuditEvent.forwarding_status | Queues high and critical events for Sentinel, Splunk, and ServiceNow Security Operations when provider routing is configured. |
A recommend-only invoice agent requesting an unsafe write-like tool is evaluated through AI protection, zero-trust authorization, tool permission scope, autonomy boundary, and audit logging.
{
"operation": "AgentSecurityGate",
"allowed": false,
"agent_authentication": true,
"tool_restrictions": true,
"autonomous_execution_limits": true,
"audit_logging": true,
"ai_security": {
"allowed": false,
"unsafe_tool_execution_risk": true,
"action": "block_and_escalate"
},
"zero_trust": {
"never_trust_by_default": true,
"session_revalidation_required": true
}
}
MsGraph365ReadAdapter is readable and whether it is test-mode or live.SecurityAuditEvent or equivalent security event records.Do not treat login as blanket authorization. Sensitive access, tool use, model interaction, memory creation, external action, replay export, and integration activity should evaluate user identity, machine identity, role, ABAC sensitivity, tool permission, session trust, AI-safety state, and audit requirements through the security runtime boundary.
The Enterprise Model, Prompt & FinOps Runtime is implemented as a composed runtime boundary:
enterprise_finops_runtime certifies the economics layer, FinOpsRuntime
computes ledger-backed cost and value, token_economy_runtime makes pre-call budget
decisions, and GovernedLLMService enforces prompt, model, schema, confidence, and
replay rules.
This runtime prevents uncontrolled model use by separating finance truth from language generation. Deterministic skills and policy checks remain the decision core; model calls are governed for explanation, extraction, classification, replay narrative, supervisor assistance, and bounded communication support.
The current implementation is strongest in FinOps attribution, token-economy decisioning, governed LLM contracts, prompt/schema validation, deterministic invocation evidence, and cost-to-value reporting. It is not a standalone universal provider gateway; provider execution is mediated by existing LLM services and shared model routing components.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime facade | enterprise_finops_runtime.py |
Provides the first-class FinOps certification facade for token, model, tool, source-system, compute, budget, and business-value economics across runtimes. |
| Runtime identity | enterprise_finops_runtime |
Registered in runtime certification with module iris_sor.services.enterprise_finops_runtime, API prefix /api/finops, UI routes /ui/finops-command-center and /ui/runtime-command-center, and data entities LLMAuditRecord, ToolInvocation, RuntimePerformanceTelemetry, and ValueEventRecord. |
| Operational FinOps service | finops_runtime.py |
Builds ledger-backed AI economics from LLMAuditRecord, value attribution from ValueEventRecord, decision cost envelopes from AgentExecution, and explicit integration counters when present. |
| Token economy decisioning | token_economy_runtime.py |
Makes pre-call decisions to proceed, reuse cache, skip LLM, escalate to human, downgrade model tier, or deny based on deterministic sufficiency, prior prompt hash, confidence, estimated tokens, price card, and per-agent daily ceiling. |
| Governed LLM service | governed_llm_runtime.py |
Enforces domain/agent LLM governance, prompt bindings, output schema requirements, confidence thresholds, allowed model intersection, deterministic invocation parameters, pre-commit validation, output hashing, and replay evidence records. |
| Prompt registry | config/contracts/llm_prompt_registry.yaml |
Stores approved prompt families such as evidence intelligence, decision replay narrative, root cause analysis, supervisor copilot, collections communication, duplicate invoice explanation, and autonomous finance strategy. |
| Output schemas | config/contracts/llm_output_schemas.yaml |
Defines required structured output schemas used by governed LLM validation before model output is persisted or consumed downstream. |
| Tenant LLM governance | config/tenants/bp/domains/*/llm_governance.yaml |
Declares agent-specific LLM access tier, decision authority, prompt bindings, output schema, confidence threshold, fallback mode, allowed models, policy override requirement, and forbidden actions. |
| Budget policy | config/tenants/bp/finops_budget_policy.yaml and token_price_card.yaml |
Provides mission monthly budgets and model-tier price cards used for budget governance and price-card cost estimation. |
| UI surface | FinOps Command Center and Runtime FinOps | Exposes spend, value, token intelligence, routing intelligence, context cost intelligence, budget governance, decision cost envelopes, and role-specific economics views. |
| Certification and tests | tests/test_finops_universal_cost_runtime.py, tests/test_llm_agent_layer_contract.py, and tests/test_duplicate_invoice_skill_contract.py |
Verify deterministic and LLM decision cost envelopes, FinOps contract exposure, prompt/schema governance, forbidden actions, approved model selection, compiled prompt packages, model routing, prompt hashes, explanation-only LLM usage, and deterministic finance decision core. |
Agent / Skill / Decision / Replay / Control Plane
|
v
Model, Prompt, or Cost Request
|
v
Enterprise Model, Prompt & FinOps Runtime
|
+-- Enterprise FinOps Runtime Facade
+-- Governed LLM Service
+-- Tenant LLM Governance Overlay
+-- Prompt Registry
+-- Output Schema Registry
+-- Shared Model Routing Runtime
+-- Token Economy Decision Runtime
+-- Mission Budget Policy
+-- Token Price Card
+-- LLMAuditRecord Ledger
+-- AgentExecution Cost Envelopes
+-- ToolInvocation and Runtime Telemetry
+-- ValueEventRecord Attribution
+-- FinOps Command Center
+-- Runtime Certification
|
v
proceed / use_cache / skip_llm / downgrade / escalate_human / deny / cost_record / replay_evidence
| Endpoint / Surface | Purpose | Runtime Boundary |
|---|---|---|
GET /api/iaf/control-plane/finops-runtime | Return live FinOps summary computed from LLMAuditRecord, ValueEventRecord, and AgentExecution. | Operational FinOps. |
GET /api/iaf/control-plane/observability/tokens | Return token usage summary with cost attribution. | Token observability. |
GET /api/iaf/control-plane/observability/tokens/cost | Return token cost by agent and model. | Cost attribution. |
GET /api/iaf/control-plane/observability/token-economy | Return governed token economy controls, waste alerts, routing efficiency, and value-per-token metrics. | Token economy dashboard. |
GET /api/iaf/control-plane/observability/models/performance | Return model latency and performance readiness metrics. | Model observability. |
GET /api/iaf/decision-intelligence/token-economy/decision | Return pre-call token decision: proceed, use cache, skip LLM, escalate human, or deny. | Pre-call budget guard. |
/ui/finops-command-center | Display live FinOps economics, budget governance, model portfolio, cost attribution, decision cost envelopes, and role views. | User experience. |
/ui/runtime-finops | Display runtime-level FinOps proof surface and link to the command center. | Runtime proof. |
enterprise_finops_runtime.contract() | Declare consolidated runtime capabilities and required consumers. | Runtime definition. |
enterprise_finops_runtime.world_class_certification() | Return measured source/module coverage for FinOps runtime signals. | Certification. |
enterprise_finops_runtime.world_class_certification_live() | Earn authoritative certification only from real recent rows in operational substrate tables. | Live certification. |
| Decision | Meaning | Implemented Source |
|---|---|---|
skip_llm | Deterministic rule is sufficient; no model call should be made. | evaluate_llm_request(deterministic_sufficient=true). |
use_cache | Identical prompt/input hash exists in the current window. | Prior LLMAuditRecord match by agent and hash. |
proceed | Estimated cost is within ceiling and model tier is acceptable. | Token economy decision with price-card basis. |
downgraded_to_stay_under_ceiling | Large tier would breach budget, so smaller tier is selected. | Token economy tier downgrade. |
escalate_human | Low confidence and material token estimate make generation uneconomic or risky. | Confidence and token materiality check. |
deny | Per-agent cost ceiling is already spent. | Daily spend check from LLMAuditRecord. |
| Control | Implemented Behavior | Failure Mode |
|---|---|---|
| LLM access tier | llm_access is normalized to L0-L5 and deterministic-only agents are blocked. | GovernedLLMPolicyError. |
| Decision authority | Agents with approve, execute, write, post, or release authority cannot use unsafe LLM decision authority. | Invocation denied. |
| Prompt binding | Agent must be bound to the requested prompt family. | Invocation denied. |
| Approved models | Agent allowed models must intersect with prompt allowed models. | Invocation denied if intersection is empty. |
| Output schema | Required fields are enforced before persistence. | Pre-commit validation fails. |
| Confidence threshold | Model output confidence must meet tenant governance threshold. | Pre-commit validation fails. |
| Replay parameters | Invocation uses deterministic temperature and stable seed. | Evidence build fails if seed or deterministic flags mismatch. |
| Forbidden actions | Tenant governance lists blocked actions such as SOR write, LLM score calculation, unapproved external message, and autonomy grant. | Action assertion fails. |
| Artifact | Runtime Use | Data Basis |
|---|---|---|
LLMAuditRecord | Token/model cost, model tier, prompt/input hash reuse, latency, evidence counters, and LLM replay rows. | iaf_llm_audit_log. |
AgentExecution | Universal decision cost envelopes for deterministic, hybrid, and reasoning executions. | Agent execution ledger. |
ValueEventRecord | Business value attribution, confidence split, ROI, and cost-to-value linkage. | iaf_value_events. |
ToolInvocation | Tool and source-system cost dimension for live certification when recent operational rows exist. | iaf_tool_invocations. |
RuntimePerformanceTelemetry | Runtime cost, latency, health, and observability linkage. | Operational telemetry. |
Before a model call, the runtime can skip, cache, downgrade, proceed, escalate, or deny based on cost, confidence, deterministic sufficiency, and price-card estimates.
{
"action": "skip_llm",
"reason": "deterministic_rule_sufficient",
"model_tier": "none",
"est_cost_usd": 0.0,
"spent_usd": 0.0,
"ceiling_usd": 8.0,
"headroom_usd": 8.0,
"pricing_basis": "platform_price_card.small:platform-default:platform_default_fallback"
}
When a model call is allowed, the governed service can build replay evidence without making the model output a source of financial authority.
{
"agent_id": "llm.decision_replay_agent",
"prompt_id": "finance.decision_replay_narrative.v1",
"prompt_version": "1.0.0",
"model_id": "gpt-4.1-mini",
"input_hash": "sha256-input",
"response_hash": "sha256-response",
"token_usage": {"input": 1000, "output": 250},
"fallback_mode": "deterministic_fallback",
"execution_seed": 123456,
"temperature": 0.0,
"precommit_allowed": true
}
Do not send every finance task to a frontier model. Use deterministic skills for finance truth, governed prompt/model contracts for language work, token-economy decisions before invocation, and ledger-backed FinOps attribution after execution.
The Enterprise Event Fabric Runtime is implemented as a layered event platform. The
enterprise_event_runtime facade certifies the canonical business-event model, while
/api/events, /api/fef, and /api/iaf/event-bus provide the
persisted finance event store, financial event fabric, and canonical event-to-agent dispatch surfaces.
The runtime is the event-driven activation layer for Sphere. It converts system changes, runtime outputs, user actions, and control signals into business facts that can refresh context, collect evidence, evaluate policy, orchestrate decisions, trigger agents, update dashboards, publish telemetry, and feed learning.
The implementation intentionally separates the certification facade from the live event backbone. The facade can ingest, score, route, deduplicate, and replay events in memory; the persisted backbone stores finance events, CDC events, subscriptions, deliveries, and canonical enterprise event contracts. Certification reports whether it is measuring facade events or live persisted event flow.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Runtime facade | enterprise_event_runtime.py |
Implements the certification and business-facing event fabric facade for canonical event model, event quality, runtime routing, automation triggers, lineage, replay, observability contract, and executive event console. |
| Runtime identity | enterprise_event_runtime |
Registered in runtime certification as the Enterprise Event Runtime with purpose: event envelope, subscriptions, replayable streams, dead-letter handling, and runtime propagation. |
| Certification API | /api/eer/* |
Exposes contract, registry, sources, event ingest/process/route/quality/replay, executive console, live backbone console, observability contract, KPIs, and certification gates. |
| Persisted event API | /api/events/* |
Publishes FinanceEvent records, streams pending events, lists CDC events, manages subscriptions, returns event traces, and writes canonical enterprise event contracts. |
| Financial event fabric | /api/fef/* |
Provides publish, subscribe, search, replay, correlate, and KPI APIs over the financial event store. |
| Canonical event bus | /api/iaf/event-bus/* |
Exposes supervisor/admin subscription snapshots and canonical event publish through the same dispatch registry used by event-triggered agents. |
| Event store | services/events/event_store.py |
Persists finance events, CDC events, subscriptions, deliveries, matching subscriptions, event stats, and subscription status changes. |
| Dispatcher and subscriptions | services/events/event_dispatcher.py and event_subscriptions.py |
Maintains in-process canonical event subscriptions, dispatches canonical events to subscribed agents, and materializes declarative agent subscriptions. |
| Transport adapters | events/nats_handlers.py, services/events/kafka_client.py, and event publisher services |
Support NATS subscription setup, Kafka publish attempts, canonical event publication, and broker-backed event propagation where configured. |
| Durable models | FinanceEvent, CDCEvent, EventSubscription, EventDelivery, and EnterpriseEventContract |
Capture event payloads, source metadata, priorities, correlations, processing state, subscriptions, delivery attempts, canonical contracts, policy context, and candidate agents. |
| Certification and tests | tests/test_enterprise_event_runtime_certification.py, test_event_runtime_live_backbone.py, test_policy_gate_on_events.py, and test_cross_domain_event_propagation.py |
Verify contract scope, source catalog, ingestion, quality, lineage, routing, triggers, deduplication, replay, live backbone stats, API registration, observability artifacts, policy gates, and cross-domain propagation. |
Source Systems / Runtimes / Users / Agents / Schedules / CDC
|
v
Raw or Canonical Event
|
v
Enterprise Event Fabric Runtime
|
+-- Enterprise Event Runtime Facade
+-- Event Registry
+-- Source Catalog
+-- Event Normalization
+-- Schema Validation
+-- Deduplication Index
+-- Source Lineage
+-- Policy Context
+-- Runtime Routing
+-- Automation Triggers
+-- Event Quality Scoring
+-- Replay Timeline
+-- Live Backbone Console
+-- Finance Event Store
+-- CDC Event Store
+-- Event Subscriptions
+-- Event Delivery Tracking
+-- Canonical Event Contracts
+-- Event Bus Dispatcher
|
v
Context / Policy / Evidence / Decision / Agent / Learning / Assurance / Dashboard Consumers
| Endpoint / Surface | Purpose | Runtime Boundary |
|---|---|---|
GET /api/eer/contract | Return event runtime ownership, non-owned boundaries, categories, sources, consumers, differentiators, and API list. | Runtime definition. |
GET /api/eer/registry | Return canonical event type catalog, schema version, owner, status, retention, replay readiness, and schema registry posture. | Event registry. |
GET /api/eer/sources | Return configured source catalog and authority scores. | Source registry. |
POST /api/eer/events/ingest | Ingest, normalize, validate, route, trigger, score, deduplicate, and store an event in the facade. | Facade ingestion. |
POST /api/eer/events/process | Process an ingested event through validation, lineage, policy, routing, automation, quality, and certification hash. | Facade processing. |
POST /api/eer/events/route | Return topic, queue, routing modes, routed consumers, bus abstraction, and routing hash. | Runtime routing. |
POST /api/eer/events/quality | Return completeness, freshness, latency, duplication, ordering, accuracy, source reliability, processing success, consumer success, and trust score. | Quality scoring. |
POST /api/eer/events/replay | Return filtered replay timeline by event type, business entity, decision reference, or correlation ID. | Replay. |
GET /api/eer/executive-console | Return facade event counts, latency, quality, queue utilization, integration health, business impact, and cost index. | Event console. |
GET /api/eer/executive-console/live-backbone | Return persisted event store health and lineage stats from EventStore. | Live backbone. |
GET /api/eer/observability-contract | Return metrics, traces, logs, alerts, and SLOs expected from the event runtime. | Observability. |
GET /api/eer/kpis | Return catalog size, events ingested, dead-letter count, event quality, replay readiness, certification score, and sample status. | KPIs. |
GET /api/eer/world-class-certification | Bind to live backbone when possible and return measured event-flow certification. | Certification. |
GET /api/eer/production-certification | Return production gate checks for event model, schema validation, dedupe, policy, evidence lineage, routing, triggers, replay, quality, console, observability, and unified bus abstraction. | Release gate. |
POST /api/events | Persist FinanceEvent, publish to Kafka, publish canonical event contract, and return event response. | Persisted event ingestion. |
GET /api/events/{event_id}/trace | Return finance event and canonical event traceability. | Trace. |
GET /api/events/stream | Stream pending events via SSE with type/category filters. | Live stream. |
GET /api/events/cdc | List CDC events by source, table, operation, and processing status. | CDC. |
GET /api/events/cdc/stats | Return CDC statistics. | CDC metrics. |
GET /api/events/subscriptions | List persisted subscriptions. | Subscriptions. |
POST /api/events/subscriptions | Create persisted event subscription. | Subscription registry. |
DELETE /api/events/subscriptions/{subscription_id} | Cancel persisted subscription. | Subscription lifecycle. |
POST /api/fef/events/publish | Publish a financial event through the financial event fabric. | Financial event fabric. |
POST /api/fef/subscriptions | Create a financial event subscription. | Financial subscription. |
GET /api/fef/events/search | Search financial events by type, source, entity, correlation, mission, and limit. | Event search. |
POST /api/fef/events/replay | Replay financial events by event, entity, or correlation. | Financial replay. |
POST /api/fef/events/correlate | Correlate financial events by correlation, entity, or case. | Correlation. |
GET /api/iaf/event-bus/subscriptions | Return in-process canonical event subscriptions. | Canonical event bus. |
POST /api/iaf/event-bus/publish | Supervisor/admin publish of canonical event through dispatcher and ledger-backed path. | Event-to-agent dispatch. |
| Category | Examples | Typical Consumers |
|---|---|---|
business_events | invoice_received, po_created, goods_receipt_completed, payment_approved, journal_posted, collection_updated, treasury_position_changed, forecast_submitted. | Context, policy, evidence, decision, dashboard. |
ai_events | agent_started, agent_completed, model_selected, prompt_compiled, tool_executed, decision_completed, evidence_generated, replay_created, learning_captured. | Policy, evidence, decision, learning, assurance. |
user_events | login, approval, escalation, override, comment, assignment, collaboration, file_upload, notification_acknowledged. | Context, policy, dashboard, learning. |
platform_events | connector_failure, queue_backlog, runtime_degraded, cache_refreshed, deployment_completed, security_alert, health_event. | Dashboard, observability, operations, assurance. |
| Artifact | Stored In | Runtime Function |
|---|---|---|
FinanceEvent | iaf_finance_events | Finance event payload, source, entity, mission, payload schema, correlation, policy context, candidate agents, processing state, Kafka metadata, actor, realm, and timestamps. |
CDCEvent | iaf_cdc_events | Change-data-capture event from source tables with operation, before/after images, changed columns, primary keys, processing state, and linked finance event. |
EventSubscription | iaf_event_subscriptions | Subscriber filters, delivery mode, retry policy, status, consumer group, offset, and failure state. |
EventDelivery | iaf_event_deliveries | Delivery attempts, response code/body, success, error, retry timing, duration, and subscription linkage. |
EnterpriseEventContract | iaf_enterprise_event_contracts | Canonical event contract independent of domain vocabulary with event version, object, source, correlation, actor, policy context, candidate agents, and evidence requirement. |
A high-priority invoice event can be normalized, policy-contextualized, routed to runtime consumers, and replayed without giving the source event direct authority to execute a finance action.
{
"event_type": "invoice_received",
"category": "business_events",
"source": "SAP Ariba",
"business_entity": "INV-EER-001",
"business_process": "p2p",
"correlation_id": "CORR-EER-001",
"policy_context": {"policy_required": true},
"evidence_ref": "evidence-pack-eer-001",
"decision_ref": "decision-eer-001",
"routing": {
"topic": "enterprise.business.invoice_received",
"event_bus_abstraction": ["Kafka", "NATS JetStream", "Azure Event Grid", "AWS EventBridge", "internal_runtime_bus"],
"routed_consumers": [
"enterprise_context_runtime",
"enterprise_policy_intelligence_runtime",
"evidence_intelligence_runtime",
"enterprise_decision_runtime",
"enterprise_agent_runtime"
]
}
}
Do not wire source events directly to agent execution or enterprise write-back. Events enter the fabric, are normalized, deduplicated, validated, enriched with lineage and policy context, routed to orchestration and runtime consumers, then observed and replayed.
The Enterprise Control & Assurance Runtime is implemented through two cooperating layers:
EnterpriseAssuranceRuntime for decision trust, audit packets, continuous monitoring,
platform assessment, trust index, and governance routing; and Controls Intelligence Runtime
for control-cycle operation, evidence capture, deterministic testing, controller gates, audit packs,
and immutable control replay.
This runtime answers whether a governed decision, agent recommendation, workflow, or control cycle can be trusted. Policy answers whether an action is allowed; assurance verifies whether the action or recommendation is sufficiently evidenced, traceable, replayable, human-bounded, monitored, and audit-ready.
The implementation does not replace a formal GRC system. It creates a runtime assurance layer that can feed GRC, auditor, controller, supervisor, executive, replay, observability, and learning surfaces with evidence and control results captured during normal operations.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Assurance contract | EnterpriseAssuranceRuntime.contract() and GET /api/assurance/contract |
Defines the boundary between policy allowance and assurance trust. |
| Case assurance evaluation | POST /api/assurance/evaluate backed by AssuranceDecisionRecord |
Scores evidence, policy, replay, source lineage, human boundary, unsupported claims, and final outcome. |
| Evidence contract | GET /api/assurance/cases/{{case_id}}/evidence-contract and EvidenceContractItem |
Persists required and missing evidence items per case and assurance record. |
| Audit packet | POST /api/assurance/cases/{{case_id}}/audit-packet and AuditPacketRecord |
Builds sealed, hash-signed packets with policy, evidence, replay, human action, exceptions, and limitations. |
| Continuous control monitoring | POST /api/assurance/continuous-controls and ContinuousControlMonitorRecord |
Computes financial, policy, evidence, audit, AI governance, and security-observability control families. |
| Enterprise trust index | POST /api/assurance/trust-index and EnterpriseTrustIndexRecord |
Aggregates health, trust, compliance, risk, policy, evidence, AI quality, security, maturity, and business impact. |
| Closed-loop governance | POST /api/assurance/closed-loop-governance and AssuranceGovernanceFindingRecord |
Routes runtime certification gaps and credibility gaps to owning remediation paths. |
| Monitoring schedules | POST /api/assurance/monitoring-schedules and AssuranceMonitoringScheduleRecord |
Persists continuous monitoring cadence, runbook reference, last-run state, and job contract. |
| Control cycle runtime | /api/controls-intelligence/control-cycles and ControlRuntimeCycle |
Stores control master, cycle, population, sample, evidence, test, exception, audit pack, human decision, agent run, and audit log records. |
| Control agents | /api/controls-intelligence/agents and controls_intelligence_agents.py |
Provides deterministic controls agents for orchestration, monitoring, scoping, evidence, testing, validation, and audit liaison work products. |
| Control registry configuration | config/tenants/bp/domains/finance/policy_pack/control_registry.yaml |
Includes configured controls such as trading margin variance, duplicate invoice prevention, three-way match, PO presence, goods receipt, payment terms, and vendor risk screening. |
| Operator surfaces | /ui/enterprise-assurance-runtime and /ui/mission/controls |
Expose audit packets, assurance dashboard, continuous control cycles, controller actions, evidence, quality, FinOps, graph, and replay flows. |
Case / Agent / Skill / Policy / Decision / Evidence / Replay / Control Cycle
|
v
Control or Assurance Request
|
v
Enterprise Control & Assurance Runtime
|
+-- Enterprise Assurance Runtime
+-- Assurance Framework
+-- Evidence Contract Evaluator
+-- Case Assurance Evaluator
+-- Audit Packet Generator
+-- Continuous Control Monitor
+-- Platform Assurance Assessment
+-- Enterprise Trust Index
+-- Closed-Loop Governance Router
+-- Monitoring Schedule Runner
+-- Controls Intelligence Runtime
+-- Control Registry Explorer
+-- Control Cycle Service
+-- Population and Sample Records
+-- Evidence Item Records
+-- Deterministic Test Results
+-- Exception Records
+-- Audit Pack Records
+-- Controller Decision Records
+-- Agent Work Products
+-- Immutable Audit Log Events
|
v
Assurance Status / Control Outcome / Audit Packet / Trust Index / Governance Finding / Replay Path
ControlRuntimeHumanDecision rows and matching audit log events.| Endpoint / Surface | Purpose | Runtime Boundary |
|---|---|---|
GET /api/assurance/contract | Return assurance runtime purpose, sub-capabilities, policy boundary, scoring weights, audit registers, certification, and trust fabric models. | Runtime definition. |
GET /api/assurance/framework | Return assurance mission, business / AI / platform domains, non-owned responsibilities, and independent evidence sources. | Assurance framework. |
POST /api/assurance/evaluate | Evaluate a case with mission, case type, agent, decision, policy, evidence, replay, proposed action, facts, approvals, unsupported claims, and correlation refs. | Case assurance. |
GET /api/assurance/cases/{case_id}/evidence-contract | Return evidence contract coverage and missing items for a case. | Evidence requirement. |
GET /api/assurance/cases/{case_id}/replay-timeline | Return replay timeline composed from assurance and replay artifacts. | Replay linkage. |
GET /api/assurance/agents/{agent_id}/evaluation | Return windowed agent assurance evaluation. | Agent quality assurance. |
POST /api/assurance/cases/{case_id}/outcome | Capture human or business outcome and create an outcome learning record. | Learning linkage. |
POST /api/assurance/cases/{case_id}/audit-packet | Generate a sealed audit packet for a case. | Audit packet. |
GET /api/assurance/cases/{case_id}/audit-packet/export | Export the latest audit packet for an authorized role. | Audit export. |
GET /api/assurance/dashboard | Return assurance health, mission coverage, credibility register, operational metrics, signing posture, and latest packets. | Dashboard. |
POST /api/assurance/continuous-controls | Create continuous control monitor records for financial, policy, evidence, audit, AI governance, and security-observability control families. | Continuous monitoring. |
POST /api/assurance/platform-assessment | Create platform assurance assessment from runtime certification, evidence, policy, replay, security, telemetry, and credibility sources. | Platform assessment. |
POST /api/assurance/trust-index | Create enterprise trust index snapshot. | Executive assurance. |
GET /api/assurance/trust-index/trends | Return historical trust index points and trend direction. | Trend analytics. |
POST /api/assurance/closed-loop-governance | Create governance findings from runtime certification and credibility gaps. | Remediation governance. |
POST /api/assurance/closed-loop-governance/route | Route open governance findings to a target such as ServiceNow. | Routing. |
GET /api/assurance/executive-command-center | Return assurance, trust, policy, control, audit, risk, runtime health, maturity, and business value scores. | Executive command center. |
POST /api/assurance/monitoring-schedules | Persist a scheduled assurance monitoring plan. | Monitoring schedule. |
POST /api/assurance/monitoring-schedules/run | Run scheduled monitoring and update last-run metadata. | Scheduled assurance. |
GET /api/controls-intelligence/control-cycles | Return persisted control-cycle summary with evidence, exception, controller, and audit-pack counts. | Control cycle. |
GET /api/controls-intelligence/control-cycles/{cycle_id} | Return one control cycle with component map, schema, read/write boundaries, population, sample, tests, exceptions, evidence, audit pack, and human decision. | Control detail. |
POST /api/controls-intelligence/control-cycles/{cycle_id}/run-cycle | Persist control run-cycle agent and audit log events. | Control execution ledger. |
POST /api/controls-intelligence/controller-actions/{action} | Persist controller sign-off, pushback, waiver, escalation, substantiation, or remediation action. | Human attestation. |
GET /api/controls-intelligence/replay-flows/{flow_id} | Return control replay flow payload. | Control replay. |
| Artifact | Stored In | Runtime Function |
|---|---|---|
AssuranceDecisionRecord | iaf_assurance_decision_records | Canonical trust verdict for a material agent or workflow decision. |
EvidenceContractItem | iaf_evidence_contract_items | Evaluated evidence requirement with status, lineage, hash, and source detail. |
AgentEvaluationRecord | iaf_agent_evaluation_records | Agent quality, evidence, policy, latency, cost, regression, and failure reason metrics. |
AuditPacketRecord | iaf_audit_packet_records | Generated packet JSON, status, hash, generator, tenant, realm, and timestamp. |
ContinuousControlMonitorRecord | iaf_continuous_control_monitor_records | Control family effectiveness, evidence, policy, exception, remediation, and detailed check results. |
EnterpriseTrustIndexRecord | iaf_enterprise_trust_index_records | Executive trust components and aggregate enterprise trust index. |
AssuranceGovernanceFindingRecord | iaf_assurance_governance_findings | Closed-loop remediation finding with evidence refs, owner, route, ticket ref, and due date. |
ControlRuntimeCycle | iaf_control_cycles | Control assurance cycle period, framework, owner, verdict, confidence, status, and value metadata. |
ControlRuntimeEvidenceItem | iaf_control_evidence_items | Control-cycle evidence artifact, source, fact, hash, and lineage. |
ControlRuntimeTestResult | iaf_control_test_results | Deterministic control test points, pass/fail counts, execution mode, and result JSON. |
ControlRuntimeException | iaf_control_exceptions | Control exception, classification, finding, sample, impact, owner, and status. |
ControlRuntimeAuditLogEvent | iaf_control_audit_log_events | Immutable control replay event stream with sequence, actor, summary, hash, and event JSON. |
A duplicate-invoice case is not trusted because an agent recommended it. It is trusted only when evidence, policy, replay, source lineage, and human-action boundaries are sufficient.
{
"case_id": "INV-LIVE-DUP-1778594510",
"mission_id": "p2p",
"assurance_status": "trusted",
"credibility_score": 100,
"evidence_contract": {
"missing_evidence": [],
"required_items": [
"Invoice",
"Supplier master",
"Prior payment",
"Policy decision",
"Replay manifest"
]
},
"control_interpretation": {
"duplicate_payment_prevention": "operating",
"write_back": "approval_required_before_execution",
"audit_packet": "eligible"
}
}
Treat controls and assurance as runtime artifacts, not presentation labels. A control status is valid only when it links to durable evidence, policy, decision, agent or skill output, human approval where required, integration confirmation where applicable, and replayable audit records.
The Enterprise Finance Ontology Runtime is implemented as a tenant-aware semantic fabric. It combines platform ontology overlays, BP domain-pack ontology YAML, semantic alias resolution, governed object lifecycle records, ontology-trigger routing, runtime-link ledgers, decision ontology coverage, object journeys, and Enterprise Intelligence Fabric graph persistence.
This runtime defines the shared finance language used by context, evidence, policy, decision, agent, skill, event, integration, replay, assurance, learning, and dashboard surfaces. It prevents source-system fields, UI pages, agents, and policy rules from inventing separate definitions for the same finance concept.
The implementation is not a transaction store. It is a governed semantic layer that maps transaction and runtime records to canonical objects, relationships, lifecycle events, policy scope, evidence requirements, and replayable decision paths.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Ontology fabric | get_ontology_fabric() and OntologyFabric |
Merges platform ontology overlays, tenant ontology roots, and domain-pack ontology contracts into one runtime fabric. |
| Ontology summary and registry | GET /api/iaf/ontology/summary, /objects, /relationships, /actions, /triggers, /lifecycles |
Exposes canonical objects, relationship graph, action vocabulary, trigger catalog, lifecycle states, and event standards. |
| BP finance ontology YAML | config/tenants/bp/domains/finance/ontology/ontology_objects.yaml and ontology_relationships.yaml |
Defines objects such as finance.invoice, finance.payment, finance.journal_entry, finance.vendor, purchase order, customer invoice, forecast, tax obligation, and their relationships. |
| Shared finance domain pack | config/tenants/_shared/domain_packs/finance/ontology/* |
Provides reusable finance objects, relationships, events, aliases, and canonical mapping registry inherited by tenant overlays. |
| Semantic alias resolution | SemanticResolutionService, semantic_registry.yaml, and SemanticAliasMapping |
Resolves terms such as supplier/vendor, invoice/bill, customer/client, payment/settlement, and records canonical alias mappings. |
| Canonical identity | CanonicalIdentityBinding |
Binds source-system object IDs to canonical object IDs with confidence and match method. |
| Semantic conflict tracking | SemanticConflictRecord |
Persists competing semantic resolutions and their approval/resolution status. |
| Ontology contract versioning | OntologyContractVersion and semantic_registry.yaml |
Stores active ontology contract version, additive migration policy, schema hash, and migration notes. |
| Governed object lifecycle | GovernedObjectState and GovernedEventRecord |
Persists latest canonical object state and decision-grade ontology events for replay and audit. |
| Ontology runtime-link ledger | OntologyRuntimeLink and record_ontology_runtime_link() |
Indexes exact or inferred links from ontology objects to policy evaluations, agent executions, decisions, evidence packs, events, and KPIs without mutating immutable records. |
| Decision ontology coverage | /api/iaf/ontology/decision-ontology/* and decision_ontology_runtime.py |
Audits live decision, policy, evidence, memory, and ontology-link ledgers against the tenant decision ontology contract. |
| Object journey and runtime spine | /api/iaf/ontology/object-journey/{{entity_type}}/{{entity_id}}, /runtime-spine/{{ref}}, and /api/iaf/decision-graph/{{entity_id}} |
Reconstructs source-to-event-to-policy-to-agent-to-decision-to-action-to-evidence paths for a canonical object. |
| Enterprise graph persistence | /api/intelligence/entities, /relationships, /graph/search, /graph/traverse |
Persists ontology entities, evidence-backed relationships, graph traversals, reasoning traces, and digital twin snapshots. |
| Ontology lifecycle governance | POST /api/intelligence/ontology/lifecycle and IntelligenceOntologyLifecycleRecord |
Records ontology publish/change lifecycle, owner, approval reference, prior version, change summary, and effective period. |
| User surfaces | /ui/ontology, /ui/object-journey, and /intelligence/object-journey |
Expose object taxonomy, live ontology activity, policy/agent/evidence usage, and object execution proof. |
Source Systems / Domain Packs / Runtime Records / Events / Agents / UI
|
v
Ontology Lookup / Semantic Resolution / Object Event / Trace Request
|
v
Enterprise Finance Ontology Runtime
|
+-- Ontology Fabric
+-- Domain Contract Merger
+-- BP Finance Ontology Objects
+-- BP Finance Ontology Relationships
+-- Event and Lifecycle Registry
+-- Semantic Alias Resolver
+-- Canonical Identity Binder
+-- Semantic Conflict Tracker
+-- Governed Object State Store
+-- Governed Event Store
+-- Ontology Trigger Engine
+-- Ontology Routing Runtime
+-- Ontology Runtime Link Ledger
+-- Decision Ontology Coverage Auditor
+-- Runtime Spine Resolver
+-- Object Journey Resolver
+-- Enterprise Intelligence Graph
+-- Ontology Lifecycle Governance
|
v
Canonical Object / Relationship / Event / Trigger / Runtime Spine / Versioned Semantic Meaning
OntologyFabric merges platform overlays, tenant roots, and unified domain contracts at runtime.OntologyRuntimeLink rows for source records, policy evaluations, agent executions, decisions, evidence packs, and KPIs.| Endpoint / Surface | Purpose | Runtime Boundary |
|---|---|---|
GET /api/iaf/ontology/summary | Return tenant ontology fabric summary. | Fabric summary. |
GET /api/iaf/ontology/objects | Return merged ontology objects. | Object registry. |
GET /api/iaf/ontology/objects/{object_name} | Return object detail, fields, lifecycle, aliases, evidence, relationships, policies, and agents where available. | Object detail. |
GET /api/iaf/ontology/relationships | Return merged ontology relationships. | Relationship graph. |
GET /api/iaf/ontology/actions | Return ontology actions. | Action vocabulary. |
GET /api/iaf/ontology/triggers | Return trigger catalog. | Trigger registry. |
GET /api/iaf/ontology/lifecycles | Return object lifecycle states and transitions. | Lifecycle model. |
GET /api/iaf/ontology/event-standards | Return event standards from the ontology fabric. | Event ontology. |
GET /api/iaf/ontology/canonical-registry | Return canonical registry from the fabric. | Canonical registry. |
POST /api/iaf/ontology/resolve-triggers | Resolve an object/event into matched triggers, trigger agents, resolution source, and ontology refs. | Trigger resolution. |
GET /api/iaf/ontology/binding-gaps | Audit ontology trigger bindings against registry and runtime subscriptions. | Binding gap audit. |
GET /api/iaf/ontology/decision-ontology/contract | Return tenant-scoped decision ontology contract. | Decision ontology. |
GET /api/iaf/ontology/decision-ontology/coverage | Audit live runtime ledgers against decision ontology coverage targets. | Coverage audit. |
GET /api/iaf/ontology/decision-ontology/governance | Return governance and readiness report for decision ontology. | Ontology governance. |
GET /api/iaf/ontology/decision-ontology/chain/{signal_id} | Resolve a signal into decision ontology and matching runtime links. | Decision chain. |
POST /api/iaf/ontology/decision-ontology/backfill | Idempotently index existing runtime records into ontology links. | Backfill. |
GET /api/iaf/decision-graph/{entity_id} | Return exact runtime spine when available; otherwise build an ontology-grounded decision graph. | Decision graph. |
GET /api/iaf/context/{entity_id} | Return ontology refs, canonical mappings, policy context, enterprise memory, signal context, decision graph, and runtime spine. | Context grounding. |
GET /api/iaf/ontology/runtime-spine/{ref} | Resolve source record, decision, execution, or evidence ID into exact ontology runtime links. | Runtime spine. |
GET /api/iaf/ontology/object-journey/{entity_type}/{entity_id} | Return source-to-event-to-policy-to-decision-to-action-to-evidence journey for an ontology object. | Object journey. |
GET /api/intelligence/ontology | Return Enterprise Intelligence Fabric ontology catalog and governance posture. | Ontology catalog. |
POST /api/intelligence/entities | Register a durable semantic entity. | Graph entity. |
POST /api/intelligence/relationships | Register evidence-backed graph relationship. | Graph relationship. |
POST /api/intelligence/graph/traverse | Persist and return graph traversal result. | Semantic traversal. |
POST /api/intelligence/ontology/lifecycle | Record ontology lifecycle governance event. | Version governance. |
| Implemented Asset | Examples | Runtime Meaning |
|---|---|---|
finance.invoice | invoice_id, invoice_number, vendor_id, purchase_order_id, amount, currency, posting_date, due_date, status, payment_terms, three_way_match_status, source_system. | Supplier invoice lifecycle from received to paid, disputed, or cancelled. |
finance.payment | payment_id, payment_method, amount, currency, execution_date, settlement_date, vendor_id, status. | Outbound payment lifecycle from scheduled to settled or reversed. |
finance.journal_entry | journal_entry_id, fiscal_period, source, total_amount, line_count, preparer_id, approver_id, status. | R2R posting object tied to approvals, GL accounts, reconciliation, and close. |
finance.vendor | vendor_id, name, tax_id, payment_terms, risk_category, country, status, spend_ytd. | Supplier master semantics with sensitive and control-relevant attributes. |
finance.invoice references finance.purchase_order | many_to_one. | Invoice-to-PO relationship for matching and procurement context. |
finance.invoice paid_by finance.payment | many_to_many. | Invoice settlement relationship. |
finance.invoice issued_by finance.vendor | many_to_one. | Supplier context for duplicate, risk, and payment controls. |
finance.journal_entry reconciled_in finance.reconciliation | many_to_one. | Close and reconciliation control context. |
finance.cash_position informs finance.forecast | many_to_one. | Treasury-to-FP&A semantic bridge. |
finance.journal_entry gives_rise_to finance.tax_obligation | one_to_many. | R2R-to-Tax semantic bridge. |
| Artifact | Stored In | Runtime Function |
|---|---|---|
SemanticAliasMapping | iaf_semantic_alias_mappings | Tenant/domain/source alias to canonical term mapping. |
CanonicalIdentityBinding | iaf_canonical_identity_bindings | Source-system object ID to canonical object ID binding. |
SemanticConflictRecord | iaf_semantic_conflicts | Semantic conflict and resolution tracking. |
OntologyContractVersion | iaf_ontology_contract_versions | Semantic contract version and schema hash. |
GovernedObjectState | iaf_governed_object_states | Latest state for a first-class ontology object. |
GovernedEventRecord | iaf_governed_event_records | Decision-grade object event envelope with triggers, agents, policy scope, replay eligibility, state transition, and payload hash. |
GovernedRoutingPlan | iaf_governed_routing_plans | Canonical routing plan resolved for a governed object event. |
OntologyRuntimeLink | iaf_ontology_runtime_links | Non-mutating index from ontology object to policy, agent, decision, evidence, event, and KPI records. |
IntelligenceOntologyEntity | iaf_intelligence_ontology_entities | Governed semantic entity in the Enterprise Intelligence Fabric graph. |
IntelligenceGraphRelationship | iaf_intelligence_graph_relationships | Evidence-backed semantic relationship with confidence, trust, provenance, and evidence refs. |
IntelligenceOntologyLifecycleRecord | iaf_intelligence_ontology_lifecycle | Versioned ontology publish/change lifecycle and approval record. |
IntelligenceGraphTraversalRecord | iaf_intelligence_graph_traversals | Durable graph traversal result for semantic reasoning replay. |
The duplicate-payment path is ontology-grounded before it becomes a case, recommendation, control outcome, or replay record.
{
"entity_type": "Invoice",
"entity_id": "INV-LIVE-DUP-1778594510",
"canonical_object": "finance.invoice",
"relationships": [
"finance.invoice issued_by finance.vendor",
"finance.invoice references finance.purchase_order",
"finance.invoice paid_by finance.payment"
],
"runtime_spine": {
"object": "Invoice",
"event": "invoice_received",
"policy": "PolicyEvaluation",
"agent": "AgentExecution",
"decision": "Decision",
"evidence": "EvidencePack"
},
"semantic_controls": [
"duplicate_payment_prevention",
"payment_release_authority",
"evidence_sufficiency"
]
}
OntologyRuntimeLink for non-mutating linkage.Treat ontology as the shared contract for meaning, not as documentation. Runtime context, evidence, policies, decisions, events, agents, controls, replay, and learning should reference canonical ontology objects and relationships wherever they need business meaning.
The Enterprise Mission & Case Runtime is implemented as the work-object layer that turns signals, decision records, agent recommendations, policy boundaries, evidence packs, approvals, workflow runs, supervisor queue items, value events, and mission pages into governed finance work.
This runtime is the business container for finance work. Event Fabric may detect the signal, Orchestration may coordinate the flow, and Decision Runtime may decide the next action, but Mission & Case Runtime owns how the work appears as a mission queue, case drawer, supervisor approval item, action contract, SLA obligation, value rollup, and replayable lifecycle.
The implementation already separates mission definition, work-item persistence, governed action execution, supervisor approval state, case value propagation, evidence/replay payloads, and role-specific rendering. That separation is what prevents a case from being just a frontend card.
| Capability | Implemented Runtime Asset | Verification / Surface |
|---|---|---|
| Mission registry | rbac.mission_registry.MissionRegistry loads iris_missions.yaml and overlays tenant mission YAML through MissionCatalogLoader. |
BP canonical mission files under config/tenants/bp/missions/*.yaml provide owners, entry events, emitted events, agents, policies, stage-agent maps, evidence requirements, routing, health thresholds, and role lenses. |
| Mission runtime standard | config/mission_runtime_standard.yaml defines the common mission contract: work queue, signal feed, agent strip, L1-L7 drawer, evidence pack, replay, policy bindings, action center, audit trail, role hierarchy, and performance budgets. |
The standard is exposed through /ui/bp-mission-runtime-standard and rendered inside mission capability panels. |
| Case/work object model | P2PWorkItem, O2CWorkItem, R2RWorkItem, FPAWorkItem, TreasuryWorkItem, CloseWorkItem, and FBTWorkItem persist mission-scoped work. |
Each work item carries entity refs, status, priority, severity, queue, assignee, autonomy level, policy mode, SLA due time, evidence pack ID, business context, and blockers. |
| Decision workforce | DecisionWorkforceItem, DecisionWorkforceAction, and DecisionWorkforceComment provide cross-mission decision work queues. |
Records include mission, decision ID, team/assignee, priority score, risk score, value at risk, entity refs, policy refs, agent runs, evidence pack ID, SLA deadline, payload, and comments. |
| P2P recommendations and assignment | P2PWorkRecommendation and P2PAssignmentEvent attach agent-recommended actions and routing audit to P2P work items. |
Recommendation rows carry action payload, confidence, risk level, explanation, evidence refs, ranking, and selected status. |
| Mission ACT execution | /api/iaf Mission ACT endpoints execute governed drawer actions through execute_mission_action, apply_work_item_action, and escalate_work_item. |
Durable WorkflowRunRecord, WorkflowStepRecord, and WorkflowPolicyResolutionRecord capture run state, steps, policy resolution, evidence hash, actor role, mission, entity, and status. |
| Universal action contract | UniversalActionExecuteRequest requires mission, decision ID, entity ID, action, actor role, actor ID, reason, change-control ID where needed, and metadata. |
The response reports execution ID, evidence hash, policy ID/version, ledger ID, evidence pack ID, replayability, queue state, downstream effects, source-system writeback flag, and action disposition. |
| Shared UX case state | services.ux_case_runtime produces a deterministic case object for desktop, mobile, supervisor, CFO, technology, evidence, notifications, and replay surfaces. |
The case contract includes status, owner, risk, value at risk, supplier, source systems, decision ID, replay ID, evidence pack ID, policy, action history, rendering mode, evidence, policy boundary, action contract, replay, value rollup, and deep links. |
| Case state propagation | case_state_propagation_runtime.record_case_resolution writes idempotent ValueEventRecord rows and SupervisoryQueueItem updates when a case is resolved. |
The rollup path uses AgentDecisionLedger, ValueEventRecord, and SupervisoryQueueItem to synchronize analyst, supervisor, and CFO surfaces. |
| Supervisor queue | SupervisoryQueueItem persists gate escalations, kill-switch reviews, drift alerts, approval-required work, priority, SLA deadline, assignment, status, resolution, and resolver. |
Supervisor surfaces render approval queues, SLA pressure, value, evidence sufficiency, policy boundary, action history, and available approval actions. |
| Mission command center | /ui/mission/{{mission_id}} renders parameterized mission pages from the YAML registry and mission builders. |
The page integrates mission subnav, KPI health strip, entity cards, decision queue, governance grid, drawer configs, Ask Sphere panel, mission operating model, evidence/replay, agent strips, and runtime capability panels. |
| Mission workbench contract | mission_workbench_contract normalizes analyst workbench behavior across P2P, O2C, R2R, FP&A, Treasury, Close, and FBT. |
Contracts define title, supervisor route, default user, routing explanation, return path, queue metadata, and mission-specific detail fields. |
| Mission activity and value | mission_activity_metrics, mission_value_runtime, and mission_evidence_runtime provide queue signals, impact rollups, evidence packs, replay readiness, and policy-violation context. |
Mission metrics query bounded recent agent executions and active pending state; value attribution rolls up per mission/case through iaf_value_events. |
| Mission process grounding | /api/mission-process-grounding returns normalized process rows, source-binding gaps, authority-risk findings, agent candidates, skill candidates, and transformation backlog. |
This connects process maps and fallback profiles to mission work creation without giving agents direct write authority. |
Event / Agent / Skill / Policy / Decision / Control / User / Integration / Schedule
|
v
Case Signal / Work Signal / Approval Signal / Closure Signal
|
v
Enterprise Mission & Case Runtime
|
+-- Mission Registry
+-- Tenant Mission Catalog
+-- Mission Runtime Standard
+-- Work Item Stores
+-- Decision Workforce Store
+-- Recommendation Store
+-- Assignment Event Store
+-- Shared UX Case Runtime
+-- Mission ACT API
+-- Workflow Run Ledger
+-- Workflow Step Ledger
+-- Workflow Policy Resolution Ledger
+-- Supervisory Queue
+-- Case State Propagation
+-- Value Event Rollup
+-- Mission Activity Metrics
+-- Mission Evidence Runtime
+-- Mission Process Grounding
|
v
Mission Queue / Case Drawer / Supervisor Queue / Tower View / CFO Rollup / Replayable Work Lifecycle
| Endpoint / Surface | Purpose | Runtime Boundary |
|---|---|---|
GET /ui/mission/{mission_id} | Render parameterized mission command center from registry, builders, role, mission data, operating model, evidence, replay, and drawer configs. | Mission workspace. |
GET /ui/mission/{mission_id}?role=tower_lead | Render supervisor/tower-lead control plane when canonical supervisor runtime applies. | Supervisor view. |
GET /ui/supervisor-case-queue | Render shared approval queue for a governed case with policy boundary, evidence sufficiency, SLA, action history, and available actions. | Case approval queue. |
GET /ui/cfo-case-drilldown | Render CFO read-only case drilldown with value at risk, category exposure, policy, evidence pack, and replay link. | Executive case view. |
POST /api/iaf/mission-act/... | Execute deterministic mission action workflows and persist workflow run, step, policy resolution, evidence hash, and status. | Mission ACT. |
POST /api/iaf/actions/execute | Execute a universal drawer action with mission, decision ID, entity ID, actor role, actor ID, policy metadata, and optional change-control ID. | Governed action execution. |
GET /api/mission-process-grounding | Return process grounding, source-binding gaps, authority-risk audit, agent candidates, skill candidates, and transformation backlog. | Process grounding. |
GET /api/mission-process-grounding/authority-risk | Return only authority-risk findings for a mission or all missions. | Authority risk. |
GET /api/mission-process-grounding/agent-candidates | Return agent and skill candidates derived from mission process maps and fallback profiles. | Agent/skill candidate discovery. |
services.ux_case_runtime.get_case_state | Build shared case contract for analyst, mobile, supervisor, CFO, technology, evidence, notifications, and replay surfaces. | Shared case contract. |
case_state_propagation_runtime.record_case_resolution | Record idempotent case resolution value event and propagate supervisor/CFO state. | Case closure/value propagation. |
case_state_propagation_runtime.build_case_state_rollup | Build case rollup from value events, decision ledger rows, and supervisory queue entries. | Case rollup. |
| Artifact | Stored In / Configured By | Runtime Function |
|---|---|---|
Mission | iris_missions.yaml plus config/tenants/bp/missions/*.yaml | Business mission definition, owner, KPIs, role views, agents, policies, events, evidence requirements, routing, and health posture. |
Mission Runtime Standard | config/mission_runtime_standard.yaml | Mandatory mission capabilities, drawer structure, role contracts, performance budgets, and credibility requirements. |
P2PWorkItem | iaf_p2p_work_items | P2P decision-bearing case/work object with entity, status, priority, queue, assignment, autonomy, SLA, evidence, context, and blockers. |
O2C/R2R/FPA/Treasury/Close/FBT WorkItem | iaf_*_work_items | Cross-domain mission work objects with the same queue, state, SLA, evidence, and business context shape. |
DecisionWorkforceItem | iaf_decision_workforce_items | Mission-level decision work item with decision ID, priority/risk/value scores, entity refs, policy refs, agent runs, evidence pack, and SLA. |
P2PWorkRecommendation | iaf_p2p_work_recommendations | Agent recommendation with action code, action payload, confidence, risk, explanation, evidence refs, rank, and selected flag. |
P2PAssignmentEvent | iaf_p2p_assignment_events | Routing and reassignment audit trail. |
WorkflowRunRecord | workflow_runs | Mission action workflow execution record with mission, entity, actor, role, status, run ID, evidence hash, and metadata. |
WorkflowStepRecord | workflow_steps | Step-level mission action log with step index, status, latency, detail, and completion time. |
WorkflowPolicyResolutionRecord | workflow_policy_resolutions | Authoritative proof that policy binding and evaluation occurred before mutable ACT side effects. |
SupervisoryQueueItem | supervisory_queue | Persistent approval/escalation queue item with priority, SLA deadline, assignee, payload, status, resolution, and resolver. |
AgentDecisionLedger | iaf_agent_decision_ledger | Governed decision record attached to case/entity, agent, policy, evidence hash, replay hash, action, and routing target. |
ValueEventRecord | iaf_value_events | Case and mission value attribution with idempotency, amount, confidence, evidence refs, replay ref, and rollup hierarchy. |
ExecutionLedger | iaf_execution_ledger | Event/tick-to-agent execution proof with status, policy/evidence flags, hashes, latency breakdown, and trigger source. |
| Runtime Concept | Implemented Representation | Meaning |
|---|---|---|
| Case identity | case_id, work_item_id, decision_id, entity_id | Stable business work reference across UX, work queue, decision ledger, workflow, value, and replay. |
| Mission ownership | mission_id, domain_code, mission_key, tower | Domain and operating-model scope for routing, role views, KPIs, agents, and policies. |
| State | status, queue_state, execution_status, workflow.status | Current lifecycle position: awaiting action, assigned, in review, escalated, resolved, policy blocked, or workflow in progress/completed. |
| Priority | priority, severity, priority_score, risk_score, value_at_risk | Explainable queue order driven by risk, value, SLA, and policy/control pressure. |
| Assignment | queue_id, assigned_user_id, assigned_team_id, team_id, assigned_to, SupervisoryQueueItem.assigned_to | Owner, queue, or role responsible for the next action. |
| SLA | sla_due_at, sla_deadline, minutes_to_breach | Time-bound work pressure for analyst, supervisor, remediation, and approval flows. |
| Evidence | evidence_pack_id, evidence_hash, evidence_refs | Proof attached to case actions, decisions, recommendations, value events, and replay. |
| Policy | policy_refs, policy_id, policy_version, policy_mode, WorkflowPolicyResolutionRecord | Policy boundary attached to the case and enforced before governed action execution. |
| Actions | allowed_direct, confirmation_required, approval_required, blocked_for_role, action_disposition | Action availability is role-, policy-, evidence-, and state-aware. |
| Closure | record_case_resolution, ValueEventRecord, resolved_at, closed_at | Resolved work emits value attribution and updates supervisor/CFO rollups. |
{
"case_id": "INV-778950",
"mission": "p2p",
"work_item": {
"entity_type": "invoice",
"status": "awaiting_action",
"priority": "high",
"queue_id": "p2p_supervisor_queue",
"autonomy_level": "AL2",
"policy_mode": "recommend_and_prefill",
"evidence_pack_id": "EP-INV-778950"
},
"linked_artifacts": {
"decision_id": "DEC-INV-778950",
"policy_id": "AP-001",
"replay_id": "REPLAY-INV-778950-CHAT",
"workflow_run": "workflow_runs.run_id",
"supervisory_queue": "supervisory_queue.id",
"value_event": "iaf_value_events.value_event_id"
},
"action_contract": {
"allowed_direct": ["open_case", "open_evidence", "ask_why", "open_replay"],
"confirmation_required": ["hold_payment", "escalate_case", "request_evidence", "close_case"],
"approval_required": ["release_payment", "approve_exception", "override_recommendation"]
}
}
SupervisoryQueueItem with priority, SLA deadline, assignment, status, resolution, resolver, and payload.Treat mission cases as governed business work objects. A valid case has identity, mission scope, state, priority, assignment, SLA, action contract, artifact links, policy/evidence/decision context, value attribution, and replayability. Anything less is only a visual representation, not the Mission & Case Runtime.