Architecture · frozen

Verifiable Consequence Boundaries

VeriSigil governs consequential AI actions at declared execution boundaries. The architectural question is whether a specific action is still authorized to become real under the conditions and exact parameters that will actually be executed.

Architecture freeze is in effect. This page is the canonical architectural explanation. It does not claim universal AI coverage, universal prevention, regulatory certification, or complete production coverage.

The boundary

AI / Agent
    │
    ▼
Identity + existing authorization / policy
    │
    ▼
VeriSigil
    ├─ current authority
    ├─ current conditions
    ├─ exact action
    ├─ exact parameters
    └─ enforcement requirements
       │
       ├── REFUSE ──► no governed external effect
       │
       └── ALLOW ───► declared protected execution boundary
                              │
                              ▼
                       external consequence
                              │
                              ▼
                 Cryptographic Execution Receipt

Architecture hierarchy

ARCHITECTURE

Verifiable Consequence Boundaries

The boundary at which consequential AI actions are evaluated and enforced.

CAPABILITY

Cryptographic Consequence Enforcement

Enforcement and evidence mechanisms binding the decision to the declared execution boundary.

RUNTIME

Runtime Authority

Authority is evaluated at consequence time rather than assumed from an earlier state.

MECHANISMS

Authority-at-Consequence

Current authority and current conditions are evaluated for the action that is about to become real.

MECHANISMS

Parameter-Locked Execution

The governed decision is bound to the exact action and parameters being executed.

MECHANISMS

Fail-Closed Runtime

When required authority or conditions cannot be established, the governed path refuses rather than assuming permission.

EVIDENCE

Cryptographic Execution Receipts

Execution outcomes can carry independently verifiable cryptographic evidence.

What makes the boundary different

Identity answers who is acting. Authorization describes what may be permitted. Policy defines rules. A gateway can provide a route. VeriSigil's narrower architectural concern is the transition from an AI-generated consequential action to an external effect: is this exact action still authorized now, and was the declared boundary actually enforced?

Evidence, not narrative

The model, agent framework, identity provider, policy system, and external actuator may change. The intended enforcement invariant is model- and provider-independent. Claims are limited by reproducible evidence.

Current proof ceiling

PROVEN / DEMONSTRATED

Receipt integrity and offline verification, fail-closed behavior, STILL adversarial testing, tamper detection, and parameter-binding enforcement on tested paths.

NOT YET PROVEN

Real Paystack transaction execution/reference, complete endpoint coverage, multi-instance distributed atomicity, and the remaining independent delegation confirmation.

NOT CLAIMABLE

Universal AI governance, regulatory certification, or a general claim that all unauthorized consequences are prevented.

Long-term direction

The architecture is intended to generalize across materially different consequence surfaces only after the invariant is proven beyond the current reference environment.

AI system / agent runtime
        │
        ▼
   VeriSigil enforcement
        │
        ├── payment
        ├── database mutation
        ├── deployment
        ├── enterprise workflow
        ├── government / external API
        └── other consequential actuator

BUILD → PROVE → GENERALIZE → INTEROPERATE → STANDARDIZE → BECOME INFRASTRUCTURE

Current phase: PROVE.

Authoritative evidence

For current claims, limitations, and validation status, use the Trust / Evidence page, adversarial challenge protocol, proof report, and claims registry.