NAIOS continues to decide what is valid, who is authorized, which evidence belongs together, when private information may be revealed, and whether anything may affect confidence or governed state. Inspect, OpenTelemetry, in-toto/DSSE, and selected policy tooling are tested only as replaceable infrastructure beneath that authority.
Evidence flows through replaceable adapters. Authority does not.
Objective, campaign, task, attempt, cohort, actor and source identities.
Frozen inputs, allowed capabilities, expected evidence and authority label.
Task, scorer, disposable sandbox, durable log, retry and inspection.
OTel/OpenInference correlation plus in-toto/DSSE-compatible subjects and digests.
Exact hashes, replay, privacy and selected deterministic policy checks.
Atomic one-use decision, receipt, qualification, confidence and promotion.
NAIOS retains
- Canonical cohort, slot, actor and evidence identity.
- Chief request-response authorization lineage.
- Private custody, phase seal and controlled unblinding.
- PostgreSQL nonce, replay, expiry, revocation and idempotency.
- Evidence qualification, confidence learning and promotion.
Frameworks may provide
- Generic task, scorer, sandbox, log and retry mechanics.
- Portable trace context and AI-specific event semantics.
- Typed evidence envelopes and signature domain separation.
- Independent verification receipt structures.
- Testable policy bundles for selected deterministic gates.
18–36 hours, phased, reversible, and evidence-producing
The three production workflows passed. Final reliability proof remains.
The later Migration 033/035 chain repaired the trusted-run boundary, passed Workflow 3 live proof and restart admission, and completed the full workflow-proof lane. The next system-level test is continuous operation: controlled restart, recovery, scheduling, and a clean new 72-hour soak.
| Component | Domain | Decision | Risk | Role / impact |
|---|