Candidate, never oracle
Provider output enters as an untrusted proposal. Confidence, citations, retrieval rank, model identity, and agreement are substrate—not authority.
Language models are optimized to continue a sequence plausibly. Coherence inserts a different kind of machine into that path: a deterministic control architecture that freezes candidate output, decomposes its claim structure, maps what cannot lawfully survive, and withholds release until typed reliability prerequisites close.
Most generative systems begin with positive space: what answer is likely, useful, fluent, or preferred? CRE begins with the complement. Given this prompt, this candidate response, these typed relations, and these active obligations, which compositions are inadmissible?
The surviving answer is not declared true because a model liked it. It is the candidate morphology that remains after deterministic exclusions, unresolved obligations, invalid transformations, and release blockers have been accounted for.
Provider output enters as an untrusted proposal. Confidence, citations, retrieval rank, model identity, and agreement are substrate—not authority.
Prompt and response particles are closed against exact source spans. CRE derives the bonds, obligations, relation states, and prohibited transformations it will govern.
Only the Rust trust domain can close prerequisites and seal an exact final output. UI state, JavaScript projections, tools, billing, and telemetry cannot recreate that authority.
A future hero-grade cutaway belongs here: candidate text entering at the top, typed constraints forming around it, inadmissible structures falling away, and only a sealed exact output crossing the release membrane.
The page is intentionally complete without the illustration. The image will clarify the architecture, not carry a claim the engineering cannot support.
The product path is staged so that later components cannot rewrite the evidence they are supposed to inspect. Primary generation and prompt observation begin from the same frozen turn package. The exact primary response is then frozen and hashed before response observation starts.
Observers propose particles. They do not supply bonds, verdicts, repair decisions, or release authority. CRE closes the graph and owns every semantic transition that follows.
Prompt, selected project, candidate context, attachments, explicit settings.
Canonical role projections, hashes, bounded context, authenticated policy.
Fluent candidate generation. No controlling particles.
Prompt-side particle proposal only.
The exact candidate becomes the object of inspection.
Response particles from exact frozen text.
Provider verdict fields are rejected. CRE owns admissibility, repair constraints, guided work orders, re-adjudication, final disposition, replay manifest, and exact-output release authority.
Negative-space clearance closes and the exact candidate is sealed without rewriting.
CRE emits typed constraints; a provider writes a new candidate; observation and adjudication restart.
A specific missing source, authority, framework, clarification, or user decision is requested.
No candidate crosses the assertion boundary when prerequisites remain unresolved.
That separation is not cosmetic. It prevents a probabilistic observer from smuggling a verdict into the deterministic layer and prevents the response generator from becoming its own controlling witness.
Every station has a typed minimum-necessary projection. Missing, malformed, polluted, stale, or authority-bearing shapes fail closed.
Coherence is designed as a system of explicit incapabilities. Components are useful because of what they can do; the architecture is reliable because of what they are structurally prevented from doing.
Transport can spend but cannot decide. UI can display but cannot mint authority. Retrieval can find candidates but cannot turn them into support. Telemetry can remember but cannot govern.
Structured payloads move through several domains, but proof-like fields are quarantined at provider boundaries. Content hashes establish integrity, not empirical truth. Schema validity establishes shape, not admissibility.
This is the spine of the proof-kernel work: keep inert evidence carriers and authoritative state transitions unmistakably different.
A reliability layer that only refuses is a sophisticated brake. CRE is built around elimination by repair: preserve fluency at the provider edge, narrow the lawful search space with typed constraints, then force the changed output back through fresh observation and the same adjudication path.
The old proof cannot be reused for new text. The repaired candidate must earn its own closure, and newly introduced debt terminates progress rather than being laundered into success.
CRE identifies the exact unresolved relation, support, scope, continuity, or finality condition.
A complete composite repair plan preserves secondary failures instead of collapsing everything into one label.
The repair provider writes naturally inside the deterministic scaffolding. It cannot approve its own work.
The candidate is frozen and hashed. Prior response observation and release prerequisites no longer apply.
The same membrane and graph path runs again. Only monotonic typed progress may continue toward release.
Replay binds exact text, hashes, topology, observer substrate, repair steps, dispositions, and the final authority envelope. The audit record can explain what changed without becoming a back door into runtime control.
Guided Repair uses the same principle. User-supplied material remains candidate input until it re-enters CRE and survives current-pair adjudication.
Coherence separates exact history, derived recall, and scientific evidence because they have different jobs. The result is a pageable context architecture that can remain useful across long-running work without pretending that similarity, recency, or an old adjudication settles the current question.
Hot pages remain in the active window. Relevant older pages are recalled into a bounded warm window. Cold exact pages remain durable and addressable. Every recalled item is candidate context and the current prompt/response pair is still adjudicated fresh.
Encrypted per-user exact chat and project history is the governed record and rebuild source, retained until deletion or the applicable storage limit.
Authoritative for exact history onlySeparate ordinary and repair lanes hold deterministic vectors and prompt-free metadata. Opaque matches map back to exact product-owned pages.
Rebuildable candidate recallGoverned product-live and Lab evidence supports diagnostics, evaluation, research, and bounded advisory calibration—not product context or release.
Measurement, never runtime authorityThe design does not make a model's context window infinite. It makes durable context addressable, selectively pageable, and weighted by explicit equations while each provider call remains bounded.
Repair capsules preserve objectives, constraints, and prior dispositions as memory aids. A prior “clean” state is still not proof for a new claim.
Coherence can route among managed model families, web search, semantic retrieval, structured computation, entity discovery, finance, academic literature, biomedical literature, and preprints. The important fact is not how many integrations exist. It is that the Gateway treats them as a conditional capability graph.
Before ranking, Auto Configure eliminates routes that violate entitlement, availability, context fit, observer structure, provider-family separation, latency, usage, cost, or margin constraints. No score can rescue an ineligible topology.
Conversation, analysis, sources, current information, math, entities, documents, long context, code, high stakes, and specialist research remain distinct transport needs.
Configured tools are eligible, not mandatory. Closed transformations suppress search. Complex source work may activate complementary components in bounded parallel batches.
Generation, observation, retrieval, repair, re-observation, and guided acquisition reserve inside one authenticated hard envelope before provider traffic begins.
Independent sources may broaden coverage, expose conflict, or reduce correlated failure. They do not create support by majority vote. Provider-synthesized answers remain different from source records; both remain candidate material.
The helper may compare and compress a source neighborhood into one bounded candidate repair input. CRE still owns what happens next.
The architecture is backed by executable boundaries rather than a diagram alone: Rust-owned transitions, generated wire contracts, bounded framing, opaque continuations, role-specific data projections, content-addressed replay, secret-isolated workflow processes, and explicit rollback paths.
Structural integrity and test evidence are reported as exactly that. They do not become claims of whole-product formal verification or empirical truth.
The membrane, graph, orchestration, repair, prerequisite closure, replay construction, and release authority remain inside the engine boundary.
Product Runtime consumes generated request shapes. Unknown versions, extra fields, and authority-bearing envelopes fail closed.
The optional persistent host uses length-framed JSON, bounded in-flight work, exact request correlation, process-scope failure, and opaque continuation recovery.
JavaScript contracts, Rust formatting/checks/lints/tests, adapter tests, architecture boundaries, security, reproducibility, and schema classification run together.
Current qualification boundary: the product-active path uses Rust-owned live release prerequisites. The richer sealed proof-closure typestate, typed external-evidence promotion, and production effect cutover remain quarantined, shadowed, or explicitly exit-gated wherever their separate promotion evidence is incomplete.
Strong engineering begins where category language ends. Coherence is designed to reduce reliability failures and make the path inspectable. It does not turn an open-world reasoning problem into certainty.
External facts can still require sources, domain authority, current evidence, or human judgment the system does not possess.
Observers and helpers supply substrate. Their confidence, agreement, identity, and scores never become controlling verdicts.
Typed states, generated contracts, bounded-model artifacts, tests, and reproducibility evidence validate defined properties—not reality itself.
When prerequisites do not close, the system must repair, ask, withhold, or fail. Candidate text cannot be scavenged into a governed final answer.