DOCUMENTATION

Architecture

Trust boundaries, module contracts and the path from proposal to verified state.

Docs menu

VISM separates decision, authority, effect and verification responsibilities. The architecture is designed to ensure that a model output cannot become a production credential or an unverified tool receipt become a success verdict.

Trust boundaries

The control plane coordinates a transition. The execution plane operates in the customer environment through structured APIs. The reasoning inspector consumes a filtered read-only evidence bundle. Write credentials stay behind a narrow effect broker/adapter boundary—not with the agent, model or generic worker.

Module contracts

ModuleBounded responsibilityImportant limitation
GatewayAuthenticate, validate typed proposals and capture idempotency context.Does not mutate production.
InspectorFind missing evidence, risks and contradictions in a scoped bundle.Advisory; no credential or decision authority.
PolicyEvaluate final plan and live context deterministically.Error or timeout never defaults to a permit.
PlannerCreate an immutable manifest with pinned targets, payloads, constraints and recovery branches.Final plan is rechecked by policy.
ApprovalBind a human assertion to the plan hash and scope.Cannot turn a hard DENY into allow.
Effect brokerValidate one-use permits and send exact typed API effects.No broad worker credential is exposed.
VerificationEvaluate independent evidence and return PASS/FAIL/UNKNOWN.Does not self-report PASS from model text.

Shared contracts

Every object includes a schema version, tenant, environment, correlation ID, actor and timestamp. Resource identity includes provider/account/region/cluster/namespace/kind/UID; a reused name is not treated as the same resource. A PlanManifest pins parent state digest, targets, preconditions, step DAG, exact payloads, policy and verification digests, recovery branches and expiry.

Transaction and effect boundary

The coordinator records intent and reservations durably before effect. The broker revalidates current approval, policy, ownership, target UID and live preconditions at the write boundary. Cloud effects are not atomic with a control database; a lost response after a write enters RECONCILING, then relies on provider state and independent verification rather than blind retry.

MEDIATION REQUIREMENT

The guarantee applies only where VISM controls the relevant write path. Unmanaged administrator keys, SSH paths, pipeline tokens or competing controllers create a coverage gap that must remain visible.