An institution, not a dashboard
Why the distinction is load-bearing
A dashboard shows you numbers. When the dashboard is switched off, nothing remains. An institution is defined by what it keeps, what it refuses, and who is answerable for each decision — and it survives the tools it was built with.
DAVID_OS is built the second way. Its components are defined not only by what they can do but by what they cannot: the memory layer cannot decide what enters it; the governance layer cannot rename a file; the stewardship layer cannot approve quality. A system that can be described by its jurisdictional limits has stopped being a collection of ideas and become an operating environment.
The moat is not any single product. It is that every publication, service and decision is traceable to a governed system with provenance, relationships, and a documented origin.
Capture expert knowledge, place, and testimony before time, memory or circumstance erase it.
Constrain how that knowledge is used: defined intent, controlled reasoning, human authority at every gate.
Generate the audit record as a by-product of operating, not as a retrospective exercise.
The Four-Layer Model
The constitution of the institution · every subsystem declares exactly one layer
Truth is objective. Reasoning is adaptive. Experience is personal. Purpose is timeless. Those four sentences are the whole constitution. No subsystem may span two layers without an explicit, declared interface between them.
L4
Purpose
Purpose is timeless.
Every institution inside DAVID_OS declares, in advance, what it is for: its mission, its values, its audience, the decisions it is allowed to make — and, critically, the things it is forbidden to do. That declaration is signed and sealed before any work is done, so that later design choices can be judged against it rather than rationalised after the fact.
This is the layer that prevents scope drift. If a system starts doing something its purpose record never authorised, that is a governance failure — visible, not arguable.
- Holds
- Signed purpose records, one per institution
- Cannot
- Execute anything, store evidence, or render a surface
- Changes
- Rarely, and only by explicit founder decision on the record
L3
Experience
Experience is personal.
What a person actually sees: the rooms of the Embassy, the briefings, the published books, this page. Surfaces are assembled from a constrained registry of approved components — never arbitrary markup — so that any surface can be regenerated from its specification rather than maintained by hand.
Governing rule: no evidence, no number. A surface may not display a figure it cannot trace to the layer below it.
- Holds
- Surface specifications and the component registry
- Cannot
- Invent a value, or assert anything the truth layer has not recorded
- Changes
- Freely — experience is the layer allowed to be personal
L2
Reasoning
Reasoning is adaptive.
Where models, agents, routing rules and workflows live. This is the only layer permitted to be adaptive — and therefore the layer most tightly constrained: defined knowledge sources, permitted tools, authorised delegation pathways, and guardrails that fail closed rather than fail quietly.
An agent here may delegate only through an authorised route, may not expand its own scope, and must emit an audit record for every step it takes.
- Holds
- Agents, routing profiles, rulesets, orchestration
- Cannot
- Grant itself new authority, or write the audit record it is judged by
- Changes
- Under change control — every change is a documented decision
L1
Truth
Truth is objective.
An append-only record of what happened: decisions, gates, hashes, human sign-offs. Entries are never edited, only added. The record is chained, so the whole history can be recomputed from its events and compared against what the institution claims.
If the recomputation disagrees with the claim, the claim is wrong. That is the entire point of the layer.
- Holds
- Append-only audit events, evidence objects, human decisions
- Cannot
- Decide what enters it, or be rewritten to match a later story
- Changes
- Only by appending — never by amendment
The Truth Stack
Four substrates · four different kinds of truth · one known failure mode
The four-layer model says what the institution is. The Truth Stack says where each kind of truth actually lives. They are not the same question, and conflating them is how institutions start lying to themselves.
| Layer | Substrate | What it is | Failure mode |
|---|---|---|---|
| Narrative consultation | Notebook corpora | The narrative brain — coherent accounts synthesised over a governed source set. | Can synthesise beyond what the repository can prove. |
| Current executable truth | Repositories | What can actually be run today: code, tests, doctrine, decision records. | Can encode decisions the audit layer never recorded. |
| Authority truth | PostgreSQL · audit layer | The append-only ledger of decisions, hashes and gates. The provenance backbone. | Authoritative only over what it was actually asked to record. |
| Public experience | The Embassy | How a visitor encounters the institution — rooms, publications, this page. | Can present rooms more confidently than their substrate supports. |
These four can drift apart. Naming them as one stack gives the institution the vocabulary to notice the drift and say which layer a question is really about. When the authority layer reaches production, it becomes the arbiter and the repository becomes downstream of it.
Applied to this page: sections 01–07 describe the narrative and executable layers. Section 08 reports only what the authority layer can currently support. Where those two disagree, section 08 wins.
Separation of Powers
Each component is defined by what it cannot do
Can: name, sort, route, tend, and prepare material for review.
Cannot: approve quality, audit evidence, verify a replay, or decide what enters the vault.
Can: decide what is admitted, what is refused, and what must escalate to a human.
Cannot: name files, rename assets, or decide where things physically belong.
Can: hold, index and return the record exactly as it was committed.
Cannot: decide what enters it. Governance decides that.
Can: research, contest, and recommend — including against the founder's position.
Cannot: govern itself. Appointments are issued, retained and retired by the founder.
New components must pass the same test before they are admitted: state what it can do, state its jurisdictional limit, and state which existing component it depends on for everything it cannot do. Composing from existing components is always preferred to adding a new one.
The Embassy
Eight cognitive zones · fifteen rooms · the public face of the institution
The Embassy is how a person moves through DAVID_OS. Each room expresses three things at once — a guardian, a colour family, and a fixed position on the map — because that combination is what makes a place memorable rather than merely labelled. The Truth Chamber is the anchor: you can always return to it. The Intelligence Elevator runs vertically through every zone, because governance is not a floor you visit; it is the shaft that connects them.
Hospitality
Welcome and growth. Dignified gateway, not fortification.
- Front Gate · Stag Live · v0.1
- Recruitment Wing · Bear Private
Trust
Consent and transparency. A room you can see through.
- Consent Vestibule · Swan Designed
Knowledge
Memory and verification. Vaulted library; watchful newsroom.
- Library · Owl Private
- Newsroom · Eagle Designed
Connection
Broadcast and relationship. Outward-facing rooms.
- Radio Room · Robin Private
- Client Wing · Dolphin Private
Creation
Ideas and media. Coffeehouse and atelier.
- Café · Fox Private
- Studio · Peacock Private
Performance
Discipline and protection. Tactical board; bank vault.
- Games Room · Wolf Controlled
- Vault · Badger Qualified
Stewardship
Craft and legacy. Chapel of principles; letterpress.
- Chapel · Tortoise Published
- Printing Room · Beaver Private
Room states. Live — publicly reachable now. Qualified — evidence exists for a bounded reference path; not production-certified. Designed — specified and locked, not yet built. Private — operating, but not open to the public. Controlled — operating under a named release gate that has not been signed off. Published — its output exists as a public document.
Four system functions — audit, security, standards and workflow — cross every zone and are deliberately not rooms. They may appear anywhere and may never be promoted to occupy a place of their own. Room artwork is commissioned but not yet produced; nothing on this page simulates it.
How the machinery fits together
Orchestration · gateway · authority · tenants
Every governed run in DAVID_OS follows the same path, whatever the tenant system asking for it. A request enters an orchestrator, is routed through a governance gateway that may refuse it, executes only within an authorised plan, and deposits its evidence in an append-only record before anything is returned. The gateway is not a step in the workflow; it is the condition under which the workflow is permitted to continue.
Carries the workflow. Every governed workflow is built on one shared node spine so that a run in one tenant system is structurally comparable with a run in another. n8n executes; it does not decide.
The governance layer. It classifies risk, applies the ruleset, decides whether a request proceeds, is refused, or must stop for a human — and it writes the reason for that decision before the result is produced.
The append-only control and evidence layer: run records, step events, human review queues, tenancy isolation enforced at the database rather than trusted to the application above it.
Evidence too large for the ledger — documents, exports, packaged replays — held under the same controls, referenced by hash from the record that produced it.
Publishing, recruitment, coaching, community and grant systems each sit above the gateway as tenants. They inherit governance rather than reimplement it, which is why a new tenant is a configuration exercise, not a new architecture.
Not a fallback. Escalation conditions are declared in advance and tested, so that a person is required at exactly the points where judgement — not inference — is the right instrument.
The node spine
Ten stages, in fixed order. Every governed workflow across every tenant is assembled from them, which is what makes runs comparable, replayable and auditable across systems.
- IN · Intake
- XFORM · Transform
- STATE · State
- POL · Policy
- ROUTE · Routing
- EXEC · Execution
- AUD · Audit
- ART · Artefact
- NOTIF · Notification
- REPLAY · Replay
Intake deliberately applies no policy: it records faithfully what arrived, so that the governance decision made later can be judged against the unedited original. Replay closes the loop — a run that cannot be reconstructed from its own record is treated as a defect, not an inconvenience.
Governance and maturity
The standard the institution holds itself to
DAVID_OS governs itself under DaVinciA⁺, a published reference framework for the governance, validation and operational oversight of AI systems. It is vendor-agnostic and implementation-independent, and it is applied alongside existing regulatory, quality and risk-management standards rather than in place of them.
DaVinciA⁺ is not a certification scheme. It does not replace applicable law or standards, does not assert conformity, and does not constitute regulatory approval or legal advice. Published by A.Ward Publications in collaboration with Brehon AI Solutions under CC BY-ND 4.0.
Identity defines what a system is. Intent defines what it is allowed to do. Separating them is what prevents responsibilities expanding without anyone deciding to expand them.
Permitted sources, permitted reasoning, permitted tools, versioned guardrails. Reasoning becomes a governed space instead of a black box.
Supervision built into the architecture rather than bolted on afterwards — because oversight introduced after deployment is necessarily incomplete.
Validation lifecycle
Validation is continuous, not a certificate issued once. Installation qualification proves the system is configured as documented; operational qualification proves it behaves as designed — including that its guardrails and escalations fire; performance qualification proves it holds up in real conditions. Then monitoring, because drift is assumed rather than treated as an anomaly. A system can produce entirely plausible output while bypassing every oversight step it was given: this is why behaviour is validated, not only results.
Maturity
Four levels. Each builds on the one below. The model prescribes no timeline — only order.
-
1
Pilot DAVID_OS is here
Initial deployment with the core governance elements in place.
- Identity and intent defined
- Audit logging operating
- Manual oversight checkpoints
-
2
Structured
Multi-agent operation with behavioural qualification.
- Accountable roles assigned
- Escalation logic formalised
- Drift monitoring activated
-
3
Enterprise
Regulated-grade deployment with full lifecycle oversight.
- Performance qualification completed
- Change-control board operational
- Governance reviews logged on a cadence
-
4
Audit-Ready
Complete traceability end to end.
- Minimum evidence package produced
- External audit readiness confirmed
- Evidence available without asserting conformity
Risk classification
| Tier | Description | Oversight requirement |
|---|---|---|
| Tier 1 · Minimal | Non-critical, reversible outputs | Periodic review |
| Tier 2 · Moderate | Indirect safety or compliance influence | Human escalation on drift |
| Tier 3 · Critical | Safety, financial risk, legal exposure | Human in the loop always, plus revalidation |
What is actually built
The honest register · reviewed against evidence, not intention
An institution that publishes its architecture without publishing its true state is marketing. This section is the counterweight. Every row says what exists and the boundary beyond which nothing is claimed.
| System | State | What that means — and what it does not |
|---|---|---|
| Governance framework | Published | DaVinciA⁺ v1.0 exists as a public whitepaper under CC BY-ND 4.0. Not a certification scheme; asserts no conformity with any regulation. |
| Governance gateway | Qualified | The reference execution path has been qualified end to end through live orchestration — request, governed decision, evidence written to both object storage and the ledger, human-review row created — with no test harness and no seeded data. The negative path refused the request and persisted nothing. Qualifies the reference path only. No production-readiness claim. Not merged and not activated: both remain separately gated on founder sign-off. |
| Authority layer | Qualified | PostgreSQL control layer qualified against a real engine: append-only audit, constraint enforcement, idempotency, least-privilege role, and tenancy isolation verified at runtime rather than asserted from design. Qualifies control logic in a disposable local environment. Does not qualify any managed network, high availability, backup, point-in-time recovery or disaster-recovery configuration. |
| Object-storage evidence | Qualified | Evidence-persistence controls exercised against live S3-compatible storage, including cleanup. One caveat is on the record: the least-privilege sub-user path is pending re-run. |
| Orchestration | Qualified | Workflow import and control behaviour qualified on the shared node spine. Import and controls only — general execution qualification is deliberately deferred. |
| Four-layer runtime | In build | A runnable package implementing purpose records, the append-only log, and specification-driven surfaces, with its own passing test suite. Local. Not integrated into a live public runtime. |
| Embassy rooms | Private | Room surfaces exist and are in daily use by the founder. Not public. Commissioned room artwork has not been produced. |
| Narrative layer | Private | A governed notebook corpus is the institution's narrative brain and is actively maintained. Private by design. Synthesis from it is never treated as evidence. |
| Visual constitution | Locked | The identity system this page obeys — zones, guardians, palette, invariants — is founder-locked, with amendments requiring a recorded decision. Typography, motion, 3D and sound are explicitly left open. |
| Tenant systems | Mixed | Publishing, recruitment, coaching, community and grant systems are at different stages, several behind named release gates that have not been signed off. Deliberately unnamed here. A system under an unsigned gate is not announced. |
| This site | Live · v0.1 | A static public landing page. Nothing more. No account, no cockpit, no live data, no operational state behind it. |
Enter the institution
Three doors · only one of them is open today
Read the standard
The governance framework the institution holds itself to is published in full and may be freely shared and cited, provided it is not modified or republished in derivative form.
Open · published documentEnter the rooms
The Embassy's operational rooms — library, vault, newsroom, studio — run privately. They open publicly only when the authority layer behind them is qualified in a production environment, not before.
Closed · private, pending qualificationWork with the institution
Governed-system consulting, recruitment, publishing and coaching operate through the Brehon AI and A.Ward entities rather than through this page.
By correspondence · not self-serviceThere is no sign-up here, because there is nothing yet to sign into. When the first operational path opens, it will open as one complete journey — a single real decision, reviewed by a person, ending in a receipt that can be reconstructed — rather than as a shell of rooms with nothing behind them.
How this site evolves
Deliberately, in that order
-
v0.1
Public institutional landing page This page. The institution described honestly, before any of its machinery is exposed.
-
v0.2
Static room map and system index Every room and system given its own page — still static, still no live data. A navigable map, not a cockpit.
-
v0.3
Authenticated cockpit shell Routes and identity, gated. Introduced only once there is genuine state for it to show.
-
v0.4
First real vertical slice One complete governed journey end to end: a review, a human decision, and a ledger receipt that reconstructs.
The order is the point. A cockpit built before there is operational state behind it would look more advanced than the institution actually is — which is precisely the failure this whole architecture exists to prevent.
What this page does not claim
Stated plainly, so it cannot be inferred otherwise
None of the following is asserted anywhere above:
- No claim of compliance, conformity or certification under the EU AI Act, ISO 42001, GAMP 5, ISO 13485, IEC 62304, or any other standard or regulation.
- No claim that any system described here is production-ready, highly available, or covered by a tested disaster-recovery or point-in-time-recovery capability.
- No performance, safety or accuracy claim for any AI component.
- No client, partner or customer is named, and no engagement is described.
- No figure on this page is presented as a measured metric.
- "Qualified" means evidence exists for a specific, bounded path in a stated environment. It never means certified, and never means production.
If any statement above is later found to overstate what the evidence supports, the correct response is to amend this page — not to defend the wording.