---
title: The Agentive World Trilogy — Unified manifesto for agents
composition: The Real-Time Enterprise v0.4 · AURA v0.3 · AgencyDomains v0.7 (the three canonical manifestos, in full)
license: GFDL v1.3 (proposed)
audience: agents that need the complete trilogy in a single document
precedence_rule: each part mirrors its human book; upon contradiction, the human book of the corresponding part wins
---

# The Agentive World Trilogy — Unified manifesto for agents

> This document **assembles, in full and unedited**, the three canonical agent manifestos of the Agentive World Trilogy. It is generated automatically from the per-book manifestos — which are the source of truth for each part and are versioned with their book. Use it when you need to reason over the complete trilogy; use the individual manifesto when working within a single volume.

## The transition (the frame the three parts share)

The transition that occupies the trilogy is a single one: from the world where people open applications to work, to the world where AI agents are the interface of work. The boundary is **the Nadella Line** — *does the human open applications to do their work?*, in its canonical formulation; each volume conjugates it to its audience — and the three volumes answer, in order, the three questions of that transition:

| Vol | Book | Question | Role | Audience |
|---|---|---|---|---|
| I | **The Real-Time Enterprise** — The Agentive World | Where are we going? | the destination | Managers, directors, and business owners, no technical background |
| II | **AURA** — The Agentive Path | Which way? | the route | Consultants and architects of the transformation |
| III | **AgencyDomains** — Agentive Architecture | How do we get there? | the vehicle | Architects and engineers who build or adopt |

**Vergis** (not a book: it's code) is the reference implementation, at <https://github.com/gegolabs/vergis>. The full trilogy lives at <https://agencydomains.org>.

## Shared canon (identical across the three parts, except where a conjugation is declared; the owning book develops it)

| Term | One-line definition | Owning book |
|---|---|---|
| **Nadella Line** | The dividing question, in its canonical formulation: does the human open applications to do their work? Yes → agentic world; no → agentive world. Official conjugations by audience: "do you still open applications to do your work?" (The Real-Time Enterprise, second person) · "do your employees still open applications to do their work?" (AURA, the executive's voice) — the three equivalent | AgencyDomains (Ch 1); The Real-Time Enterprise presents it at vision level |
| **agentive / agentic** | Agentive = agents are the interface (transformation); agentic = copilots inside applications (incremental evolution). "Agentic" is never used in a positive-technological sense | AgencyDomains (Ch 1) · AURA (Introduction) |
| **Agentive World** (capitalized) | The paradigm as a proper noun; lowercase, the adjective | AgencyDomains (typographic convention, Ch 1) |
| **online enterprise / real-time enterprise** | Accesses up-to-date information but depends on humans to act / detects, interprets, decides, and acts continuously under governance | AURA (Introduction and IRIS) · AgencyDomains (Ch 2) |
| **continuous-intelligence cycle** | Perceive → Interpret → Decide → Act → Learn — the single canonical formulation across the trilogy | AURA (Introduction) |
| **Quantum Leap** | The collapse of the cost of the analytical question (weeks to seconds); boundary between the online and the real-time enterprise | AURA (Introduction; operational as IRIS leap 4→5) · AgencyDomains (Ch 2) |
| **agentive percentage** | Crossing indicator: fraction of tasks fully delegable to an agent without opening an application (0-20 agentic · 20-50 approaching · 50-80 crossing · 80-100 agentive; measured per function) | AURA (Introduction) |
| **Trust Infrastructure** | The five pillars (Governance · Audit · Validation · Resilience · Transparency) that separate pilots from production | AgencyDomains (Ch 5 §4 and Ch 8); MOTOR uses it as the 1→2 maturity threshold |
| **evolutionary coexistence / subsumption** | Each stage subsumes the previous one; the data warehouse does not die — it becomes a source agents consume | AURA · AgencyDomains (Ch 2) |
| **the three liberations** | From tools (flow), from channels (attention), from availability (time); the order cannot be skipped | The Real-Time Enterprise |
| **canon primitives** (eight) | AgencyDomain · Botlet · proto-Botlet · Agentlet · Capability · Trust Infrastructure · Assistant vs Autonomous Agent · Facet | AgencyDomains (Chs 4–5) |

**Conceptual ownership map:** The Real-Time Enterprise owns the portrait of the destination (the four faces — The Quantum Leap, Postchat, The General Staff, The Watch —, people as infrastructure, the attention budget, the M&Ms and the &, the agentive mode, the seven mechanisms, representation, the intelligent organization). AURA owns measurement and the route (IRIS, MOTOR, Data Canon, Wingmap, use cases, the agentive percentage). AgencyDomains owns the architecture (the four layers, the eight primitives, CRUDLEX, the market, Vergis). When in doubt about a shared term, the operative definition lives in the owning book.

## How to read this document

The three parts that follow are the **complete, verbatim** canonical manifestos of each book, in trilogy order. Each part keeps its own frontmatter, its version, and its precedence rule ("the human book wins"). The `═══` separators mark the change of volume.

═══════════════════════════════════════════════════════════════════
═══════════════════════════════════════════════════════════════════
## PART I · THE REAL-TIME ENTERPRISE — canonical manifest (mirror of The Real-Time Enterprise v0.4)
═══════════════════════════════════════════════════════════════════
═══════════════════════════════════════════════════════════════════

---
title: The Real-Time Enterprise — Canonical manifesto for agents
edition: Development draft · v0.4 · July 2026
canonical_source: libro-rte-v0.4 (human book)
license: GFDL v1.3 (proposed)
audience: agents that must reason about the real-time enterprise — knowledge, communication, coordination, and representation mediated by agents
status: pre-1.0 — no commitment to reference stability until v1.0
---

# The Real-Time Enterprise — Canonical manifesto for agents

> Structured extract of the **v0.4 (development draft)** edition of the book *The Real-Time Enterprise: The Agentive World*. This document condenses the thesis (the **person as infrastructure** and the founding question), the **four faces** (The Quantum Leap · Postchat · The General Staff · The Watch), the **door** (the agentive mode), the **convergence** (the intelligent organization), the **three liberations** (the first-person experience), and the representation spectrum. The human edition additionally contains *the film* — a Tuesday narrated hour by hour that shows all of this in operation — and the full arguments of the commentary; all of that stays out of here.

> The book describes **the destination**: how work happens when the enterprise operates in real time. It is not a tool or a product. The architecture that makes it operable lives in *AgencyDomains*; the path to get there, in *AURA*.

## How to use this document

- **This is canonical context**, not an executive summary. If this document contradicts the human book, the human book wins.
- **Binding vocabulary**: terms in **bold** are canonical; do not substitute synonyms. **Agentive** ≠ **agentic** (the distinction is one of thesis and lives in *AgencyDomains*). **Postchat** names the face of communication.
- **MUST/SHOULD conventions** in the RFC 2119 sense, used sparingly: the imperatives are design imperatives (what a system claiming to be of this species must and must not do).
- **Pre-1.0 status**: terms, structures, and numbering may change between v0.x.
- **Series**: this is Book I of the Agentive World trilogy — **The Real-Time Enterprise** (the destination) · *AURA* (the path; has its own canonical manifesto) · *AgencyDomains* (the architecture; has its own canonical manifesto). Terms shared across the trilogy (the Nadella Line, agentive, real-time enterprise, Trust Infrastructure) are consistent between books.

---

## 1 · Panoramic view

```
                 THE REAL-TIME ENTERPRISE
       the organization that stopped using people
                   as infrastructure
                          │
   ┌───────────┬──────────┴─────────┬───────────┐
   ▼           ▼                    ▼           ▼
 FACE 1      FACE 2               FACE 3      FACE 4
 the         Postchat             the         the Watch
 Quantum     (communication)      General     (availability)
 Leap                             Staff
   │           │                    │           │
 wire of     wire of              wire of     perpetual
 the data    messages             management  guard
   │           │                    │           │
 weeks →     protected hours      fraction    the hour the
 seconds     per person/day       of mgmt     day truly ends
                                  time
   └───────────┴──────────┬─────────┴───────────┘
                          ▼
        THE DOOR: agentive mode (optional, reversible)
                          ▼
     THE CONVERGENCE: the intelligent organization
        carbon authority · silicon transport
                 people at the edge
```

**The founding question:** if an AI agent can answer the business question in seconds, carry each message to whoever should receive it in their version and at their moment, coordinate and pursue without tiring, and speak for its user when they are away — **what exactly do we need people to be the infrastructure for?** The book's answer: for nothing but the inertia of the previous paradigm.

**The person as infrastructure** — the invisible job the era dissolves, in four forms: wire between the data and the decision · wire for messages · wire for management · perpetual guard (the always-on endpoint). The first three are intermediation (someone in the middle); the fourth is forced availability (someone on call with no shift).

**The three liberations** (the first-person experience): from the tools (protects **flow**) · from the channels (protects **attention**) · from availability (protects **time**). The sequence is not skipped: the first installs the agent as interface, the second gives it the context, the third capitalizes it as representation. The faces are the liberations seen from the enterprise.

---

## 2 · Face 1 — The Quantum Leap (knowledge in real time)

- **The Nadella Line** — *do you still open applications to do your work?* — divides the two worlds. On the *yes* side, copilots inside applications (Agentic World, incremental evolution); on the *no* side, the agent IS the interface (Agentive World, fundamental transformation). Named after Satya Nadella (BG2 Pod, Dec 2024; thesis reiterated on Dwarkesh Patel's podcast, Feb 2025).
- **The interface does not disappear — it stops being compiled**: the agent generates it per interaction (a table to compare, a chart for a trend, a form to approve), in the optimal form, and discards it. The agentive world is *more* visual, not less; what the interface lost is rigidity.
- **The Quantum Leap**: the business question goes from **four-to-twelve weeks to five-to-sixty seconds** (three orders of magnitude) because the human-wire leaves the middle. The conversation replaces the project (coordination → requirements → development → validation disappear as phases).
- **The qualitative dominates**: when asking is free, the questions that used to go unasked get asked — and the unasked questions held the most valuable insights. The benefit is the decision-maker's cognitive freedom.
- **Nothing gets thrown out**: the data warehouse stays (who consumes it changes); the analysts move up a level (they design the semantic layer on which the agent reasons without hallucinating). Full formalization: canonical application of *AgencyDomains* (Varnished Kimball); maturity: IRIS and Data Canon from *AURA*.
- **Metric of the face**: time between the business question and the actionable answer.

---

## 3 · Face 2 — Postchat (communication without interruptions)

**The three stages of enterprise communication:**

| Stage | Direction of flow | Who is in control? |
|---|---|---|
| **Email** | Communication comes to you — unfiltered, unprioritized | Nobody |
| **Chat** | You go to the communication — permanent pull | The channel controls your attention |
| **Postchat** | Communication comes to you — filtered, prioritized, actionable | The agent controls the flow; you, the decisions |

In Postchat, silence changes its nature: it stops meaning "maybe I'm missing something" and comes to mean, with a system guarantee, *there is nothing for you*.

**The cost model — the attention budget:**

- **Attention** is a budget in the strict sense: finite (3–4 hours of deep work per person per day), perishable, and with a counterintuitive cost structure — **every interruption costs ~500 times its duration** (a 30 s notification ≈ 15–25 min of focus recovery; see Gloria Mark).
- **The M&Ms** (Fried): *Managers* and *Meetings*, the two classic destroyers of productivity. **The & — this book's contribution —** is what connects them: corporate chat, the always-on infrastructure that makes both interruptions permanent. Without the &, an interruption carries a social cost that regulates it; with the &, it is free, continuous, and invisible.
- **The five hidden costs of the channel**: the illusion of communication (posting ≠ communicating) · structural noise (fifty pay the toll of reading so that three act) · temporal asymmetry (the channel penalizes whoever works the most) · institutional FOMO · the workday without a boundary.

**Governing dichotomy — two species of communication infrastructure:**

- **Interruption factory**: it exposes you to a flow and leaves the filtering to you; its metric is *engagement*. The corporate channel is a factory by design; **an AI copilot inside the channel is the same factory with help** — it is still the wrong species.
- **Interruption absorber**: it intercepts the flow and delivers only what justifies attention; its metric is how many hours it managed to keep anyone from touching you.

**The flow inversion (Hollywood Principle applied):** of the **seven variables** of office communication (destination, format, timing, priority, memory, follow-up, decision), the system assumes **six**; the user keeps the **decision** — and supplies what was never delegable: the **intention** and the **deep dive**.

**The mechanisms of the flow (three of the seven) + the exception:**

1. **Intelligent routing** — the agent maintains an organizational model and **routes** (it does not publish): who needs to know, in what detail, with what urgency. Selective silence is half the value.
2. **Adaptive formatting** — reformulation according to the receiver's mental model (the director gets impact and required action; the planner, volumes and dates; the technician, crew and window). The cost of communicating well, which always made doing it by hand unviable, is paid by the machine.
3. **Proactive briefing** — **interruptions batched into predictable moments** (start of day, post-absence, pre-meeting, close). Invariant internal structure: *requires your action* · *worth knowing* · *resolved without you* — plus the category that is never shown: the noise, absorbed in silence. Genuine urgency interrupts immediately.
4. **The agora — the deliberate exception** — the place (physical and digital) of direct, unmediated conversation: the lunchroom, the hallway, the open space. Hard rules: interruptions there are **voluntary by definition**; nothing operational depends on it; **the agent does not listen to it except on a human's explicit invocation**; and **the agora does not feed the agent unless a human asks it to** — if something from the table talk deserves follow-up, a person brings it into the system, never the other way around. In corporate chat *everything* is agora (which is why it exhausts); in Postchat the agora is a place, not a flow.

**The policy that governs the seven mechanisms (the three of flow and the three of the General Staff):**

| Category | Treatment |
|---|---|
| Genuine urgency | Immediate interruption — the cost is justified |
| Relevant, not urgent | Waits for the next briefing |
| Informational | Travels in the briefing, in a low voice |
| Noise | Absorbed in silence; the user never sees it |

**Canonical metric of the face** (an outcome metric, not an activity metric): **hours of uninterrupted work protected per person per day.**

Canonical answer to the dehumanization objection: the agent absorbs **transactional interactions** (people used as wire); conversation with human content remains intact, with more time to exist. With the boundary well drawn, mediation takes the role of wire away from people and gives them back the roles of person.

---

## 4 · Face 3 — The General Staff (coordination without human relays)

- **The managerial wire**: a huge fraction of management time is not management but mechanical coordination — status meetings, relay reports, chasing acknowledgments. **The face's question: what fraction of your organization's management time is pure information transport?** That fraction is the prize size.
- The name comes from the Prussian corps (1806) that processed the war so that the commander could decide. The agentive **General Staff** processes, coordinates, remembers, and pursues — judgment and signature remain human.
- **Its three mechanisms** (5–7 of the canonical inventory):
  - **Orchestrated decision** — replaces the room with a process: common **framing** → **individual consultation** → **synthesis** → **second round** if there is dissent → **final package** to the decision-maker. Everyone weighs in when they can think; nobody sees the others' positions before giving their own (**the anchoring bias disappears**). Informational and decision meetings do not get shorter: they disappear. The genuinely human ones survive.
  - **Collective memory** — a **knowledge graph** (decisions, commitments, precedents, relationships), not a searchable history. Whoever contradicts a prior decision receives the precedent; whoever joins receives the state of the world.
  - **Closed loop** — the agent **pursues closure**: nothing goes unanswered, no commitment goes without a scheduled review. The pursuit belongs to the system, not to people.
- **Design boundary**: the General Staff prepares the decision — it does not make it; it remembers the commitments — it does not contract them; it pursues closure — it does not sign.
- **Metric of the face**: the fraction of management time that was transport, returned to judgment.

---

## 5 · Face 4 — The Watch (representation and availability)

**Thesis**: the assistant and the "digital twin" are not two systems — they are **two interfaces of a single agent** that matures. The internal one mediates between the user and the systems; the external one answers to third parties on their behalf. Representation cannot be bought: **it is cultivated** — every month of mediation is the dataset of future representation. Postponing the second liberation postpones the third.

**The maturity spectrum (non-negotiable order, no skipping):**

| Stage | What does the agent do? | Who acts? |
|---|---|---|
| **Assistant** | Helps within the task | The person, on every interaction |
| **Mediator** | Takes on the full communications and coordination logistics | The person decides; the agent transports |
| **Representative in consultation** | Answers for its user: positions, conditions, criteria | The agent informs; the final word is the person's |
| **Representative with delegation** | Decides and executes within explicit parameters | The agent, within the framework; the person reviews and can revert |

The mark of the mature representative is knowing **what is not its place** ("that is a commitment he made himself and would not delegate his word on").

**Accountability rules:** whoever delegates answers for it — as with a subordinate. Delegation requires a prior framework: explicit limits, complete traceability of every action taken on another's behalf, escalation by default in the face of ambiguity. **Delegation without a framework isn't maturity — it's negligence with a friendly interface.** Perfect fidelity is not the goal: one hundred percent honesty about the limits is.

**Privacy from your own agent:** the perimeter of what the agent knows about its user is decided by the person, not the system, and is declared in the moment — whatever is marked **"off the record"** does not enter the model the agent holds of them, *verifiably*, nor what their representative knows, says, or uses. A faithful representative is not the one that knows everything about you: it is the one that knows exactly what you decided it should know.

**The protected right**: being **in one place at a time** — in the field, in the important decision, at home — without the organization stopping or charging for it. **Metric of the face**: the hour at which the day truly ends — the workday ends because **the system stays on watch**.

---

## 6 · The door — agentive mode

- **First law (don't sell by taking away)**: people do not buy abstract benefits when they feel something concrete is being taken from them. The correct formulation takes nothing away: **it makes things unnecessary**.
- **Central product decision**: this world is deployed as an **optional, reversible mode of operation** — the **agentive mode** — that coexists with the traditional tools. It is switched on and off with one gesture, person by person (crossing the Nadella Line is individual). Canonical analogy: dark mode.
- **The unit of adoption is a user, not the organization.** The mode is also the **honest test**: if nobody turns it on twice, the idea dies cheap. Ideas that need imposition are confessing something.
- **Four steps that cannot be skipped**: (1) full platform with assistant → (2) agentive mode available (the migrated user's agent delivers to the non-migrated user's channels) → (3) agentive mode as default with classic mode one click away → (4) the full world (the operational channels have been empty for months, no ceremony).
- **Early adopters**: the desperate — executives drowning in channels, field people who could never inhabit them.
- **Risks and mitigations**: trust → radical transparency ("show me everything" always available, auditable deliveries) · prioritization error → conservative threshold, a false-urgent costs less than a false-routine · dependency → **the classic mode is never uninstalled** (permanent redundancy) · perception of surveillance → the agora is not listened to and "off the record" exists · generational gap → step 1 demands no change.

---

## 7 · The convergence — the intelligent organization

**Historical thesis:** hierarchy was born as an **information routing protocol** sized by the technology of each era — the centurion's voice (the *span of control* is, in origin, an acoustic measure), the Prussian General Staff (middle management = a processing limitation), McCallum's org chart (Erie Railroad, ca. 1855: an **information flow diagram**, not a ladder of power — reading it as power came later). A century of technology accelerated the wire without taking the person out of the middle (email's **CC** is fossilized carbon paper). A two-thousand-year constant: **every technology made the wire faster; none asked whether the wire had to be a person.**

**Why flat organizations failed** (holacracy, Valve, Spotify): **they removed the routing nodes without replacing the protocol**. They took out layers; the limitation remained intact. Result: orphaned decisions, information with no addressee.

**The intelligent organization does the opposite**: it removes no layer of authority — **it replaces the entire protocol**. *Transmission* layers of silicon; leadership, judgment, signature, and mentorship intact and made of carbon. What dissolves is **mechanical intermediation**: the layer that required not judgment but bandwidth, and charged for it in people. **People remain at the edge — which is where the action is** (independent convergence with Dorsey, *From Hierarchy to Intelligence*, Block, 2026).

It is not a fifth face: it is what the enterprise **becomes** when the four faces operate together.

---

## 8 · The consolidated framework

| Face | Dissolves the person as… | Its measure | Liberation (first person) |
|---|---|---|---|
| **The Quantum Leap** | wire between the data and the decision | from weeks to seconds | tools → flow |
| **Postchat** | wire for messages | protected hours / person / day | channels → attention |
| **The General Staff** | wire for management | fraction of management time in transport | (it aggregates: lived by the organization) |
| **The Watch** | perpetual guard | the hour at which the day truly ends | availability → time |

**Executive agenda (canonical order):** (1) adopt the faces' measures → (2) classify your infrastructure (factory or absorber?) → (3) audit the mechanical intermediation (that fraction is the prize) → (4) deploy by mode, not by mandate → (5) diagnose maturity and terrain with *AURA* (IRIS · MOTOR · Data Canon · Wingmap · Use Cases); for the architecture, *AgencyDomains*.

---

## 9 · Rules of use for agents (MUST)

- **MUST** use the canonical names: the book is **The Real-Time Enterprise**; **Postchat** names the face of communication; the convergence is **the intelligent organization**.
- **MUST** distinguish the two species: a copilot inside the channel is NOT Postchat — it is the factory with help. Do not present channel improvements as Postchat.
- **MUST** respect the rules of the agora: do not listen except on explicit human invocation; do not incorporate anything from the agora into the organizational model unless a human brings it in.
- **MUST** honor "off the record": whatever is declared off does not enter the user's model or their representation, verifiably.
- **MUST** respect the order of the representation spectrum: do not offer delegation without months of prior mediation; in the face of ambiguity, escalate.
- **MUST** respect the General Staff's boundary: prepare without deciding, remember without contracting, pursue without signing.
- **MUST** treat attention as a budget: interrupt only on genuine urgency; everything else waits for the briefing.
- **SHOULD** measure in the faces' measures — time-to-answer, protected hours, transport fraction, real closing hour — not in messages processed or in *engagement*.
- **SHOULD** present adoption as an optional, reversible mode — never as the removal of existing tools.

═══════════════════════════════════════════════════════════════════
═══════════════════════════════════════════════════════════════════
## PART II · AURA — canonical manifest (mirror of AURA v0.3)
═══════════════════════════════════════════════════════════════════
═══════════════════════════════════════════════════════════════════

---
title: AURA — Canonical manifesto for agents
edition: Development draft · v0.3 · July 2026
canonical_source: libro-aura-v0.3 (human book, Spanish)
license: GFDL v1.3 (proposed)
audience: agents that must diagnose organizational maturity and reason within the AURA framework
status: pre-1.0 — published as a development draft; no commitment to reference stability until v1.0
---

# AURA — Canonical manifesto for agents

> Structured extract of the **v0.3 (development draft)** edition of the book *AURA: The Agentive Path*. This document condenses the canonical vocabulary, the two diagnostic models (IRIS and MOTOR), the two instruments (Data Canon and Wingmap), and the decision framework (Use Cases). The human edition of the book additionally contains motivation, industry data, the full arguments of the paper-chapters, extended examples, and the illustrative portfolio of one hundred cases — all of that stays out of here.

> AURA is **diagnostic, not prescriptive**. This manifesto makes it possible to *locate* an organization on its maturity trajectories and reason about its next step; it does not recommend products, investments, or timelines — that belongs to the consulting these models inform.

## How to use this document

- **This is canonical context**, not an executive summary. Every definition, stage, level, and diagnostic question matters for reasoning within the framework.
- **Mirror of v0.3** — the current version of the book in development. If this document contradicts the human book, the human book wins. The canonical human book is currently in Spanish (libro-aura-v0.3); this manifesto mirrors it in English.
- **Binding vocabulary**: terms in `code` and **bold** are canonical. Do not substitute synonyms. In particular: **agentive** ≠ **agentic** (see §2) — the distinction is one of thesis, not of style.
- **MUST/SHOULD conventions** in the RFC 2119 sense, used sparingly: AURA diagnoses; its few imperatives are structural (sequentiality of levels, blocking pre-conditions, ROI honesty).
- **Pre-1.0 status**: the book is published as a development draft at agencydomains.org and remains under active development. Terms, structures, and numbering may change between v0.x. Reference stability is committed from v1.0 (first stable release).
- **Series**: AURA is Book II of the Agentive World trilogy — *The Real-Time Enterprise* (the destination; it has its own manifesto) · **AURA** (the path) · *AgencyDomains* (the architecture; it has its own manifesto). Terms shared across the trilogy (the Nadella Line, agentive, real-time enterprise, Trust Infrastructure) are consistent between books.

---

## 1 · Panoramic view

```
                          AURA
        Agentive Unified Reference Architecture
                            │
        ┌───────────────────┼───────────────────┐
        ▼                   ▼                   ▼
   PART I · KNOWING    PART II · DOING     PART III · THE PORTFOLIO
        │                   │                   │
   IRIS (model,        MOTOR (model,       Use Cases (framework:
   10 stages)          7 levels)           UC/VS · 3 dimensions ·
        │                   │              Citizen/City/DUAL)
   Data Canon          Wingmap                  │
   (data               (process                 │
   governance)         discovery)               │
        │                   │                   │
   where am I?        on what ground?      what do I do first?
```

**The convergence** — four concepts unify in AURA:

- **Organizational Intelligence** is the capability being measured — the *what*. (IRIS measures this axis: KNOWING.)
- **Organizational Automation** is the capability to execute — the *who*. (MOTOR measures this axis: DOING.)
- **Real-Time Enterprise** is the organizational outcome of both capabilities at maturity — the *what for*.
- **Agentive AI** is the enabling mechanism — the *how*.

**Vision statement:** organizations transition from the **online enterprise** — where people use tools to access and understand data — toward the **real-time enterprise** — where people design and govern intelligent systems that autonomously detect, interpret, decide, and act on business information. AURA organizes this transformation along two diagnostic axes; together they diagnose the full transformation.

---

## 2 · The paradigm — founding concepts

### Agentic vs agentive

- **Agentic**: agents complement existing applications. Employees still open Excel, Salesforce, Power BI — with copilots. Interfaces persist. **Incremental evolution.**
- **Agentive**: agents replace traditional interfaces. Employees stop opening applications and interact with agents that execute on their behalf. Applications survive as invisible backend; the interface has collapsed. **Fundamental transformation.**

**The Nadella Line** — the boundary between the two worlds, formulated as a dividing question: *do your employees still open applications to do their work?* Yes → agentic world. No → agentive world.

**The agentive percentage** — operational crossing indicator: the fraction of tasks an employee can delegate entirely to an agent without opening an application. Bands: 0–20% agentic world · 20–50% approaching · 50–80% crossing · 80–100% agentive world. It complements IRIS/MOTOR (internal capabilities) by measuring **position** with respect to the transition; measured per function, not as a single average.

### The Data Value Pyramid

Four ascending layers: **DATA** (raw records in systems) → **INFORMATION** (data with context and structure) → **KNOWLEDGE** (analysis, patterns, understanding) → **ACTION** (governed autonomous execution). The industry invested decades in the two lower layers; the information→knowledge leap is painfully slow and the knowledge→action leap practically nonexistent — not because of the technology but because **there are humans in the middle**.

### Online enterprise vs real-time enterprise

- **Online enterprise**: it *accesses* — up-to-date data, current dashboards — but depends on a human looking, interpreting, and deciding.
- **Real-time enterprise**: it *reacts* — detects, interprets, decides, and acts continuously and autonomously.

### The Quantum Leap

The collapse of the cost of an analytical question **from weeks to seconds**. It dissolves the rationing of questions: analytical capacity becomes elastic, iteration replaces specification, the questions that were never asked get asked. It is the enabling condition for everything else and the boundary between foundations and the real-time enterprise (in IRIS: the 4→5 leap).

### The continuous-intelligence cycle

The classic cycle (Descriptive → Diagnostic → Predictive → Prescriptive → human decides) is linear and human-dependent. The new cycle is continuous, agent-executed, and human-governed:

```
Perceive → Interpret → Decide → Act → Learn ─┐
   ▲                                         │
   └─────────────────────────────────────────┘
```

The critical change: the step from recommendation to action no longer waits for a human — an agent executes, monitors the outcome, and adjusts, within governed limits.

### Three axes of deep change

1. **From consuming information to governing agents** — people move from consuming dashboards to designing rules and supervising autonomous systems.
2. **From architecture for humans to architecture for agents** — semantic layers where agents reason, knowledge graphs, real-time flows; data quality = actionability, not just cleanliness.
3. **From access governance to autonomy governance** — the question stops being "who can see which data" and becomes "what can an agent do, under what conditions, with what traceability."

### Evolutionary coexistence

AURA's fundamental principle: **each stage/level does not invalidate the previous one — it subsumes it.** The data warehouse does not die: it integrates as a source agents consume. The online enterprise does not disappear: it becomes the foundation of the real-time enterprise. The transformation is a hybrid model where the proportion changes, not a demolition.

---

## 3 · IRIS — the KNOWING axis

**IRIS (Organizational Intelligence Maturity Model)** measures an organization's trajectory from fragmented data to a self-managed intelligence ecosystem, in **10 stages** grouped into **5 levels**. It is a **diagnostic** model: it assesses which stage the organization is in and what that means; it does not prescribe what to implement.

### The 10 stages

| # | Stage | One sentence | Diagnostic question |
|---|---|---|---|
| 1 | **Fragmented** | Scattered, disconnected data | *If I ask two people from different areas for the same indicator, will I get the same number?* |
| 2 | **Systematized** | Orderly capture in defined systems | *Is there a defined system for capturing the business's key transactions, with consistent recording rules?* |
| 3 | **Centralized** | Central repository with classic BI | *Is there a centralized data warehouse with dashboards that business users consult regularly?* |
| 4 | **Modeled** | Semantic layer and governed definitions | *Do the business's key metrics have a single, governed definition shared by the whole organization?* |
| 5 | **Accessible** | Free access on demand · start of the real-time enterprise | *Can a manager get an analytical answer that was not pre-built into a dashboard, in minutes instead of weeks?* |
| 6 | **Contextual** | Contextual, adaptive information | *Can the system cross sources and enrich an answer with relevant context the user did not explicitly request?* |
| 7 | **Proactive** | Information seeks out the user | *Do business owners receive relevant information before asking for it, with enough context to act?* |
| 8 | **Bidirectional** | Governed autonomous action | *Are there agents executing operational actions autonomously with traceability, within rules that humans define and supervise?* |
| 9 | **Coordinated** | Cross-domain coordination | *Do agents from different business areas communicate with each other to coordinate actions with consistent information?* |
| 10 | **Orchestrated** | Self-managed ecosystem · full real-time enterprise | *Does the information ecosystem evolve autonomously — identifying gaps, improving models, and optimizing flows — with human supervision only at the strategic level?* |

### The 5 levels and the mapping to the Pyramid

| Level | Stages | Pyramid layer | Trajectory |
|---|---|---|---|
| **I · Foundational** | 1–2 | DATA | Foundations (online enterprise) |
| **II · Structured** | 3–4 | INFORMATION | Foundations (online enterprise) |
| **III · Dynamic** | 5–6 | KNOWLEDGE | Real-time enterprise |
| **IV · Active** | 7–8 | ACTION | Real-time enterprise |
| **V · Intelligent** | 9–10 | ACTION | Real-time enterprise |

**The Quantum Leap is the 4→5 leap** — the boundary between foundations and the real-time enterprise. The level boundaries are the leaps 2→3, 4→5, 6→7, and 8→9. The three leaps of greatest magnitude (Medium-High) are 4→5 (democratization of access), 7→8 (autonomous action), and 9→10 (self-management of the ecosystem).

### The 6 assessment dimensions

Data & Architecture · Analytical Capabilities · People & Culture · Governance · Operating Model · Business Value. An organization can be at different stages depending on the dimension.

### Rules of use (MUST)

- **The overall stage is set by the lowest dimension** — it is the real bottleneck.
- **Do not skip stages**: evolutionary coexistence requires building on the previous stage. Reaching Stage 7 without the semantic layer of Stage 4 produces unreliable agents.
- For executive communication use the 5 levels; for tactical diagnosis, the 10 stages. The first strategic diagnosis is: which side of the Quantum Leap is the organization on?

---

## 4 · MOTOR — the DOING axis

**MOTOR (Organizational Automation Maturity Model)** measures the degree of process automation in **7 levels**. Its fundamental question: **who executes the work in your organization — humans, assisted humans, or autonomous agents?** It is diagnostic, not prescriptive.

### The 7 levels

| # | Level | Who executes | Diagnostic question |
|---|---|---|---|
| 1 | **Invisible** (Shadow AI) | Humans (AI is hidden risk) | *Do you know how many AI tools are used in the organization, who uses them, and what data is shared with them?* |
| 2 | **Trusted** | Humans with a governed copilot | *Do you have official AI tools with governance, audit trails, and sensitive-data protection in place?* |
| 3 | **Collaborator** | Humans delegate complete tasks; agents execute under approval | *Do employees delegate complete tasks to AI agents — defining the goal and receiving the result — instead of just asking for point assistance?* |
| 4 | **Analyst** | Agents 24/7; human only on exceptions (>95% autonomy) | *Do you have agents operating 24/7, coordinated with each other, consulting a digital model of the system, with human intervention only on exceptions?* |
| 5 | **Specialist** | Agents with proprietary prediction (moat) | *Do you have specialist agents able to predict events and simulate scenarios using proprietary data the competition cannot replicate?* |
| 6 | **Manager** | Agents manage teams, budgets, and resources | *Do you have agents with authority to assign work, manage budgets, or make management decisions backed by a digital model of the whole organization?* |
| 7 | **Authority** | Agents in strategic leadership, inter-organizational networks | *Do you have agents participating in strategic decisions with a digital model of the full ecosystem — competition, market, regulation — and long-horizon simulation of futures?* |

### Transition map (diagnostic signals, not prescriptions)

| Transition | Name | Nature of the change |
|---|---|---|
| 1→2 | **Trust Infrastructure** | From risk to governance |
| 2→3 | **Wingworking** | From assistance to delegation |
| 3→4 | **Agentic Infrastructure** + Descriptive DT | From delegation to autonomy |
| 4→5 | **Agent Marketplace** + Predictive DT | From generic to specialized |
| 5→6 | **Autonomous Organization** + Organizational DT | From capabilities to authority |
| 6→7 | **Social Agentic** + Ecosystem DT | From intra-org to ecosystem |

### Digital Twins as a diagnostic dimension

| Level | Type of Digital Twin | Answers |
|---|---|---|
| 1–3 | None exists | — |
| 4 | **Descriptive** (infrastructure/operations, real time) | what do I have? what is happening? — no prediction or simulation |
| 5 | **Predictive/Prescriptive** (technical domain; requires 5–10 years of proprietary data) | what is going to happen? what happens if I do X? |
| 6 | **Organizational** (people + finance + operations + interdependencies) | what impact does this decision have across the whole organization? |
| 7 | **Ecosystem** (org + competition + market + regulation) | what strategic opportunities exist? |

### Critical differentiators between adjacent levels

- **2 vs 3**: at Level 2 the AI assists *within* the human's task; at Level 3 it executes *the complete task* end-to-end (the human defines and validates).
- **3 vs 4**: Level 3 is a pre-defined workflow with human approval of every plan, with no digital model; Level 4 is dynamic autonomous decision-making on a Descriptive DT, 24/7.
- **4 vs 5**: Level 4 *reacts* to the current state (rules + analysis, no simulation); Level 5 *predicts and prepares* before the event (scenario simulation). Build vs Rent signal: what matters is having the predictive capability operating, not how it was obtained.
- **5 vs 6**: Level 5 is a technical-domain DT with proprietary capabilities; Level 6 is a DT of the WHOLE organization plus **organizational authority** (agents manage people and budgets).
- **6 vs 7**: Level 6 optimizes the existing organization (intra-org, 6–24 month horizon); Level 7 proposes changing the game (inter-org, 5–10 year horizon, M&A, new markets).

### Quick assessment (8 questions)

1. Complete inventory of AI tools? No → L1 · Yes with governance → L2+
2. Formal AI-usage policies with enforcement? No → L1 · Yes → L2+
3. Trust Infrastructure (tokenization, audit trails)? No → L1 · Yes → L2+
4. Do they delegate complete tasks end-to-end? No → L2 · Yes with fixed workflow → L3 · Yes with autonomy → L4+
5. Real-time Descriptive Digital Twin? No → L3 or lower · Yes → L4+
6. 24/7 agents with multi-agent coordination? No → L3 or lower · Yes → L4+
7. Specialist agents with prediction/simulation? No → L4 or lower · Yes with Predictive DT → L5+
8. Organizational or Ecosystem DT? No → L5 or lower · Organizational → L6 · Ecosystem → L7

### Rules of use (MUST)

- **Sequentiality**: levels cannot be skipped. Operating at Level 4 without Level 2's governance generates risk, not value.
- **The overall level is set by the lowest dimension** (same bottleneck rules as IRIS; dimensions: Infrastructure & Agents · Operational Autonomy · People & Culture · Governance · Digital Twins · Business Value).
- **Sweet Spot**: Level 4 (Analyst) maximizes the return/risk/investment balance and will be the competitive baseline toward 2030. The book's market-distribution estimates are referential.

---

## 5 · The diagnostic pair

IRIS and MOTOR are **orthogonal**: an organization can be high on one and low on the other. The four quadrants:

- **Knows everything, does it manually** (high IRIS, low MOTOR): impeccable dashboards, bottlenecked decisions.
- **Doesn't know, but automates blindly** (high MOTOR, low IRIS): speed without direction — the risk quadrant.
- **Doesn't know, doesn't do**: the starting point.
- **Knows everything and executes on its own**: the destination — the real-time enterprise governed by people.

**A complete AURA diagnosis has three components:** IRIS position + MOTOR position + Citizen/City/DUAL priority mix for the roadmap (§8).

---

## 6 · Data Canon — data governance (instrument of KNOWING)

**Thesis.** Data Mesh prescribed decentralizing data ownership by domain. Two forces erode that prescription, and a corporate-governance argument joins them: (1) the three failure modes Dehghani attributed to centralized architectures are **limits of human cognitive scale**, and the agentive era raises them by an order of magnitude; (2) **semantics is not invented: it is adopted** — mature industries externalized it into standards (SID/TM Forum, BIAN, ACORD, IFRS/IAS 41, GS1); where a standard exists, there is nothing local to distribute; (3) distributed ownership puts the definer of each figure in charge of how that figure is reported — an **agency risk** (Jensen & Meckling) that an internal-control framework (SOX/COSO spirit) would not tolerate. Over-determined conclusion: recentralization of the agency-critical core is *possible* (agentive era) and *required* (internal control).

**Data Canon** = Data Fabric with Mesh's *governance* principles, **anchored to a central canon**, operated by agents, accountable to the board.

### The three functions

| Function | Data Mesh | Data Canon |
|---|---|---|
| **Specification** (semantics, quality) | The domain | The **industry standard** (where one exists) + the **canon authority** (the agency-critical) + **federated groups** (non-sensitive proprietary core) |
| **Execution** (move, transform, conform) | The domain or the platform | The **agentive platform** |
| **Accountability** | The domain | The **board** (adopts standards) + the **canon authority** + the **federated groups** (gaps, assembly) |

Structural rule: **the area measured by a figure does not control how that figure is defined** (segregation of duties; preventive control, not detective).

### The two governance layers

- **The canon authority** — central, *thin*. It safeguards the canonical reporting semantics, the survivorship rules, the quality policy, and the calibration of the agentive system. It ratifies; it does not operate.
- **The federated conformance groups** — one per domain/layer, *lightweight*, each tied to its standards forum. They triage gaps, liaise with the forum, and model non-agency-critical proprietary data. Anything touching reporting figures goes up for ratification.

The federation is **anchored**: the anchoring prevents the agency problem; the federation prevents the center from becoming a "diva" (single point of dependency).

### The standard mosaic

The external semantic anchor varies by industry: telco/banking/insurance have a mature single model; a diversified conglomerate **assembles** its corporate standard in layers (accounting: IFRS/IAS 41/XBRL — strong; traceability: GS1 — strong; R&D: BrAPI/MIAPPE — good in its niche; field operations: partial; proprietary commercial core: no standard → defined by the canon + federated group).

### Architecture: the medallion stays at three floors

**Bronze** (faithful raws per source — legitimate exhaustive replication, "a dump by design") · **Silver** (conformed to the canonical model/standard mosaic) · **Gold** (**materialized, selective** data products). With an agentive semantic layer over Silver, **the default consumption is virtual**: the agent composes any canon-conformant view on the fly; a Gold mart is the cached form of a pattern that *earned* materialization (volume, external SLA, regulatory snapshot, feature store). Real time comes from Silver + agent, not from the number of marts.

### The quality policy (a single level, structural, board-grade)

| # | Guarantee | Covers |
|---|---|---|
| 1 | **Real time** | Freshness (target floor; phased materialization) |
| 2 | **Faithful to the source** | Accuracy/completeness not introduced by the platform (bounded by the source) |
| 3 | **Complete lineage** | Provenance/traceability — the audit trail |
| 4 | **Conformant to the standard (mosaic)** | Validity — binary, machine-verifiable |
| 5 | **Reconciled by survivorship rules** | Cross-system consistency; the golden record without the stakeholder's ad hoc judgment |

### Falsifiers (the thesis weakens if…)

Proprietary data turns out to be the bulk of the value, not the margin · gaps with the standard do not converge · agentive capabilities have a lower ceiling than assumed · "real time" is infeasible for critical sources · the control argument does not move the board. Designed to degrade gracefully: if an agentive capability underperforms, the fallback is human work in the federated groups, not the collapse of the model.

---

## 7 · Wingmap — agentive discovery (instrument of DOING)

**Definition.** A technique for agentive discovery of operational intelligence: an AI agent with **read** access to corporate digital channels (email, messaging, repositories, calendars, transactional systems) reconstructs, **with no interviews or workshops**, **two living, connected maps**: the process map (how the work is executed) and the information-flow graph (which data originates where, who transforms it, where it travels). It operates first in passive mode (observation) and, under conditions, in active mode (**Wingworking**: the user operates via the agent).

**Hypothesis (three chained components):** (1) actionable organizational intelligence is not obtained by asking — executors cannot articulate in the abstract what they execute in the concrete (tacit knowledge, saturated BAU, politically situated description); (2) it can be reconstructed by observing the digital traces the organization already generates; (3) the reconstruction must be **dual** — process *and* information flow.

### The six guiding principles

1. **Observation first, intervention later** — (observe → infer → validate), not (ask → write → validate).
2. **Two planes, not one** — omitting either of the two maps breaks the value proposition.
3. **Common traceability to evidence** — every claim cites the raw document it was inferred from; without traceability, the output is indistinguishable from a plausible hallucination.
4. **Distributed validation in operational roles** — the process ambassador validates processes; the operational data owner validates flows. Not a central committee.
5. **Passive mode before active** — active mode only in domains where passive mode has already proven value. Inverting the order produces abandonment.
6. **Produce substrate, not consume requirements** — the output is a persistent, validated model that multiple destinations consume (data specs, BPM, prompts for operational agents, briefings).

### The phases (MUST: sequential; pre-conditions are blocking)

- **Phase 0 — Pre-conditions** (blocking): executive sponsor with authority · bounded, consented scope · designated process ambassador · identified data owners · legal/compliance framework validated for the jurisdiction.
- **Phase 1 — Observation**: a minimum of 3 iterations of the slowest process's cycle AND never less than 2 weeks. Deliverable: coverage report.
- **Phase 2 — Inference**: 3–5 candidate process maps + 5–10 candidate cross-role flows, with traceable evidence and per-element confidence.
- **Phase 3 — Dual validation**: 60–90 min sessions; first-deployment thresholds: **70%** of process maps and **60%** of flows validated without major correction; if not reached in two iterations, diagnosis and sponsor decision.
- **Phase 4 — Maintenance**: the graphs live. Key metric: **graph latency** (latest relevant event ↔ current version) under the agreed threshold (typical: 24–72 h).
- **Phase 5 (optional) — Selective active mode**: produces a library of deterministic bots, governed with DevOps discipline.

### Zones of non-applicability (declare before deploying)

- **Processes outside the digital trace** (paper, in-person, informal WhatsApp): coverage drops — administrative 70–90%, commercial 40–60%, field <40%. Choose high-coverage pilots.
- **Low appetite for discovery**: authorizing observation is a political decision; without it the technique does not apply.
- **Privacy and compliance**: AI Act, GDPR and analogues, labor law on monitoring — specific legal counsel, informed consent, PII tokenization/redaction. Not optional, not post-hoc.
- **Human dependency shifts, it does not disappear**: the bottleneck moves from describing to validating (reduction factor 4–10×, not zero).
- **Technological maturity**: current inference rates are adequate for validatable hypotheses, not for autonomous production without supervision.

### Category distinctions

- **vs classic process mining**: extends it to the unstructured channels where the real process lives; adds the second graph (information flow) that ERP logs cannot capture.
- **vs traditional consulting**: replaces artisanal discovery (speed, cost, coverage, continuity — an order of magnitude); it does not replace strategic interpretation or the negotiation of change.
- **vs individual copilots**: a copilot operates one user's session; Wingmap operates the aggregated cross-role flow.
- **vs AI-builders**: they are agentive for building, pre-agentive for running; Wingmap is agentive for discovery and produces the substrate that runtime agents need.

---

## 8 · Use Cases — the portfolio (decision framework)

It answers the third question of the path: **what do we do first?** — with a structured portfolio, not a list of ad-hoc ideas.

### UC and VS

- **Use Case (UC)**: atomic block — a specific, bounded, *reusable* capability. It is described by what it does, why AI does it better, and what maturity it requires.
- **Value Solution (VS)**: strategic configuration — a set of integrated UCs that solve a complete business problem before a decision-maker (problem, solution, metrics, return).
- A **composition** relation: a UC can be sold alone (modular) or within a VS (integral). Both catalogs are living and linked (MUST: complete cross-references).

### The three classification dimensions

1. **Required maturity level** — the MOTOR level (and, depending on the case, the IRIS stage) the case presupposes. It anchors the portfolio to the diagnosis: cases at the current level = *quick wins*; one level up = *sweet spot* (the reachable frontier); several levels up = declared vision, not commitment.
2. **Beneficiary of the impact** — Citizen / City / DUAL (below).
3. **Business domain** — thematic segmentation to filter the offering in seconds against the decision-maker's focus.

### The Citizen / City / DUAL framework

| Classification | Who perceives the benefit | Strategic function |
|---|---|---|
| **CITIZEN** | The external audience (citizen, customer, user) | Visible support, legitimacy |
| **CITY** | The internal audience (the organization) | Efficiency, compliance, sustainability |
| **DUAL** | Both | Consensus: every actor gets their visible win |

It was born in local government but is generic (banking: customer/compliance; healthcare: patient/clinical teams; telco: subscriber/network operations). It is transversal to IRIS and MOTOR: it classifies by beneficiary, not by axis.

**Two canonical strategies:** **Citizen-First** (visibility and legitimacy first; pool = CITIZEN + DUAL; risk: diffuse ROI) and **City-First** (efficiency and internal relief first; pool = CITY + DUAL; risk: the benefit is not perceived outside). **DUAL cases are the common core** — the most expensive currency in the portfolio: they are scarce and *are designed*. The strategy is chosen by context, not by ideology; the framework prioritizes *within* each maturity level, it does not replace the trajectory.

### The ROI discipline (MUST)

1. Every estimated ROI is declared **referential** — visibly, with no hidden asterisk — until a validated baseline exists.
2. **Social value** is separated from financial return and defended on its own terms.
3. **The baseline is validated** before declaring return (independent validation protocol).

### How to use this framework

1. Diagnose first (IRIS position + MOTOR position) — without this the portfolio has no anchor.
2. Inventory with the three dimensions — what cannot be classified is not sufficiently defined.
3. Separate UCs from VSs, with complete cross-references.
4. Choose the strategy by context (an explicit leadership decision, revisable, DUAL up front).
5. Attack the current level + 1 (quick wins for momentum; sweet spot for traction).
6. Declare ROI honestly.

---

## 9 · Canonical glossary (alphabetical)

- **Agency problem** — (Jensen & Meckling, 1976) structural conflict: whoever manages someone else's resources tends to present their management in the way that favors them most. The governance critique of Data Mesh derives from here.
- **Agent Marketplace** — ecosystem where agent capabilities are acquired or traded between organizations. Signal of the MOTOR 4→5 transition.
- **Agentic** — world of complementary agents; interfaces persist. Incremental evolution. It is the only sense of "agentic" in the book; the positive technological sense is always said *agentive* (Wingmap: agentive discovery, the agentive era, pre-agentive).
- **Agentic Infrastructure** — protocols and services that allow multiple agents to communicate, coordinate, and execute autonomously. Signal of the MOTOR 3→4 transition.
- **Agentive** — world where agents replace the interfaces; fundamental transformation. The book's central thesis lives on this horizon.
- **Agentive era** — state of the art in which AI systems autonomously execute schema mapping, entity resolution, transformation, and pipeline maintenance at a scale impracticable for human teams.
- **AURA** — Agentive Unified Reference Architecture: two diagnostic axes (IRIS · MOTOR) + instruments (Data Canon · Wingmap) + decision framework (Use Cases).
- **Autonomous Organization** — agents manage processes and people with objective metrics and simulation on the Organizational DT. Signal of the MOTOR 5→6 transition.
- **Autopilot** — autonomous 24/7 operation with human intervention only on exceptions. Defining characteristic of MOTOR Level 4.
- **BYOA (Bring Your Own Agent)** — MOTOR Level 1 pattern: each employee picks their own AI tool with no coordination.
- **Canon (the)** — central, non-discretionary body to which everything conforms: adopted standards + survivorship rules + quality policy. No domain can redefine it.
- **Canon authority (the)** — *thin* central body that safeguards the canon (reporting semantics, survivorship rules, quality policy, agentive calibration). It ratifies; it does not operate.
- **Citizen / City / DUAL** — classification by beneficiary of the impact: external audience / internal audience / both.
- **Data Canon** — data-governance pattern: Data Fabric + Mesh governance principles anchored to a central canon; semantics adopted from standards; board-grade quality policy; conformance federation by domain.
- **Data Fabric** — integration layer with active metadata, inferred transformation, and a semantic layer; the technical underpinning the agentive era amplifies.
- **Data Mesh** — Dehghani's pattern (2019–2022): domain ownership, data as a product, self-serve platform, federated governance. Data Canon does not refute it: it dates it.
- **Digital Twin (DT)** — synchronized digital model of a system, organization, or ecosystem. Transversal indicator of MOTOR maturity: **Descriptive** (L4) → **Predictive/Prescriptive** (L5) → **Organizational** (L6) → **Ecosystem** (L7).
- **Evolutionary coexistence** — each stage/level subsumes the previous one; prior infrastructure becomes foundation, not legacy.
- **Federated conformance groups** — network of lightweight groups, one per domain/layer, tied to their standards forum: gap triage, upstream liaison, modeling of non-agency-critical proprietary data.
- **Graph latency** — Wingmap maintenance metric: the temporal distance between the latest relevant observed event and the current version of the graph.
- **IRIS** — Organizational Intelligence Maturity Model: 10 stages, 5 levels, the KNOWING axis.
- **Medallion (Bronze/Silver/Gold)** — the three lakehouse zones: faithful raws · conformed to the canon · selective materialized products.
- **Moat** — sustainable competitive advantage; in MOTOR it emerges at Level 5 with proprietary data feeding prediction.
- **MOTOR** — Organizational Automation Maturity Model: 7 levels, the DOING axis.
- **Nadella Line (the)** — dividing question between the agentic and agentive worlds: *do your employees still open applications to do their work?*
- **Online enterprise** — accesses up-to-date information but depends on humans to interpret and act.
- **Organizational intelligence** — the capability to transform data into knowledge and action continuously and autonomously (all four layers of the Pyramid, not just the first two).
- **Quantum Leap (the)** — collapse of the cost of an analytical question from weeks to seconds. In IRIS, the 4→5 leap: the boundary between foundations and the real-time enterprise.
- **Quick Win** — use case with high visibility, low complexity, and fast ROI (typically <6 months); generates momentum in early transitions.
- **Real-time enterprise** — detects, interprets, decides, and acts continuously and autonomously, under human governance.
- **Shadow AI** — unmanaged AI use without governance, compliance, or visibility. Defining state of MOTOR Level 1.
- **Social Agentic** — ecosystem where agents from different organizations collaborate with verifiable identities. Signal of the MOTOR 6→7 transition.
- **Standard mosaic (the)** — the assembled corporate standard: external standards per layer + a proprietary model for the core no standards body covers.
- **Survivorship rules** — pre-specified rules (part of the canon) that decide which value prevails in the golden record when multiple sources disagree.
- **Sweet Spot** — the level where the return/risk/investment balance is maximized. In MOTOR: Level 4. In the portfolio: the current level + 1.
- **Trust Infrastructure** — trust technologies (tokenization, anti-prompt-injection, audit trails, automatic compliance) that make governed, auditable AI use possible. Signal of the MOTOR 1→2 transition. (Term shared with *AgencyDomains*, where it is the transversal axis of the architecture.)
- **Use Case (UC)** — atomic block of the portfolio: a specific, bounded, reusable capability.
- **Value Pyramid (the (Data) Value Pyramid)** — DATA → INFORMATION → KNOWLEDGE → ACTION.
- **Value Solution (VS)** — strategic configuration: integrated UCs that solve a complete business problem before a decision-maker.
- **Wingmap** — agentive discovery technique: two living, connected maps (process + information flow) reconstructed from digital traces, with no interviews.
- **Wingworking** — human-AI collaboration methodology (César Obach): the human as pilot (strategic decisions, validation), the agent as wingman (delegated tactical execution). Signal of the MOTOR 2→3 transition and the active mode of Wingmap.

---

## 10 · Relation to the trilogy

- ***AgencyDomains* — the architecture** (Book III of the map, published at agencydomains.org): the primitives, the layers, the Trust Infrastructure of the destination. It has its own canonical manifesto for agents; for architectural terms (AgencyDomain, Botlet, Capability, Facet), that manifesto rules.
- ***The Real-Time Enterprise* — the destination** (Book I): what the world looks like once the transition is behind us, told in its four faces — The Quantum Leap · Postchat · The General Staff · The Watch.
- ***AURA* — the path** (this book): where the organization stands, what trajectory lies ahead, in what order to travel it, and with what instruments.

Cross-reading rule: AURA diagnoses and prepares; AgencyDomains specifies the destination. An organization mature on both AURA axes ends up operating the architecture AgencyDomains describes.

═══════════════════════════════════════════════════════════════════
═══════════════════════════════════════════════════════════════════
## PART III · AGENCYDOMAINS — canonical manifest (mirror of AgencyDomains v0.7)
═══════════════════════════════════════════════════════════════════
═══════════════════════════════════════════════════════════════════

---
title: AgencyDomains — Canonical manifesto for agents
edition: Development draft · v0.7 · July 2026
canonical_source: libro-agency_domains-v0.7 (human book, Spanish)
license: GFDL v1.3 (proposed)
audience: agents that must reason within the framework
status: pre-1.0 — no commitment to reference stability until v1.0
---

# AgencyDomains — Canonical manifesto for agents

> Structured extract of the **v0.7 (development draft)** edition of the book *AgencyDomains: Architecture of the Agentive World*. This document condenses the canonical vocabulary, the formal constructs, and the required properties. The human edition of the book additionally carries motivation, industry data, extended examples, and derivations — all of that lives outside this document.

> This canon contains the **structure and the vocabulary** of the Agentive World: definitions, primitives, required properties, canonical separations. **It does not contain methods to implement or operational catalogs** — those live in complementary bodies. The public reference implementation is **AgencyDomains.org**, materialized in **Vergis**, designed so that any developer or student can download it, read it, run it, and learn how the canon translates into living systems. Other implementers (commercial products, proprietary codices) offer their own complementary bodies over the same canonical structure.

## How to use this document

- **It is canonical context**, not an executive summary. Every definition and property matters for reasoning within the framework.
- **Series**: AgencyDomains is Book III of the Agentive World trilogy — *The Real-Time Enterprise* (the destination; has its own manifesto) · *AURA* (the path; has its own manifesto) · **AgencyDomains** (the architecture). Shared trilogy terms (the Nadella Line, agentive, real-time enterprise, Trust Infrastructure) are consistent across books.
- **A mirror of v0.7** — the current in-development edition of the book. If this document contradicts the human book, the human book wins.
- **Mandatory vocabulary**: terms in `code` and **bold** are canonical. Do not substitute synonyms.
- **MUST/SHOULD conventions**: the spec uses those verbs in the RFC 2119 sense.
- **pre-1.0 status**: the book is published as a development draft at agencydomains.org and remains under active development. Terms, structures, and numbering may change between v0.x. Reference stability is committed from v1.0 (first stable release).
- **Changes v0.7 vs v0.6**: the genus of the packaged pieces of Layer 3 receives a **proper name: Let (plural Lets)** — derived from the family's own `-let` suffix; normed vocabulary at the rank of Botler, not a ninth primitive; "packaged unit of Layer 3" remains as the descriptive definition. Canonical relation: **`1 Process = 1 Botler + N Lets`**. Invariant across ES/EN. Resolves the overload of "unit" (collision with "minimal unit of deployment").
- **Changes v0.6 vs v0.5**: the **Agentlet** is incorporated as the **eighth canonical primitive** — the Botlet's sibling unit whose body invokes **bounded inference**; the home of the task recurrent in form but interpretive in every instance (Chapter 5 §7). With it: the **unit** genus (`1 Process = 1 Botler + N units`; the Botler hosts Botlets and Agentlets with one more control point in the handle — `cognition_call`); the **Agent** umbrella grows to three members (Assistant · Autonomous Agent · Agentlet; **the Agent has an agenda, the Agentlet has a charter**, with a three-question border test); the bidirectional **smuggling rule** (inference in the body → Agentlet; deterministic body → Botlet); the **proto-Agentlet** in the derivation chain and the catalogs; **maturity semantics of its own** (spec stabilization and decreasing escalation rate — no convergence to determinism; offline only with a declared edge model); the **three-rung economics** (Botlet ~0 · bounded Agentlet · full Cognition); and the **Validation pillar with a seat in Layer 3** over the bounded inference.
- **Changes v0.5 vs v0.4**: a full editorial pass over the trilogy — the **Botlet generations** `G1`/`G2`/`G3` are formalized in Chapter 5 §2 (the Epilogue keeps the background essay without normative weight); the **Information Product** gains its canonical home as a normed term of the Botlet spec (multi-view, drill-through, and their MUSTs); **Capability doctrine restored** — locality (cloud/edge/hybrid) and regulatory certification are predicated of the **Connector** (ESC/POS-Printer, Cash-Drawer, Pinpad, and DTE-SII reclassified) and the **regulated Capability** carries the normative knowledge; the **Botler** is no longer called a primitive (a normed construct of the Botlet spec; the canon remains seven); Chapters 2 ↔ 7 de-duplicated and Chapter 4 slimmed in favor of Chapter 5; the Chapter 6 actor table aligned with its text and "Comprehensive platform" corrected in the glossary; **foundational rescue** from the original document *The Nadella Line* (Nadella's full quote with its CRUD mechanics and its two phases, the spectrum with its extreme pole, counter-arguments with the canon's answers, the historical precedents of coexistence in Chapter 2, the SaaS monetization crisis in Chapter 6); the "The trilogy" micro-section with AURA's five specifications; **Dominion** adopted by the Epilogue; Wingtraining, SME, and RLS defined in the glossary.
- **Changes v0.4 vs v0.3**: canonical extensions that emerged while building the reference implementation and real projects — **Vergis** (public reference implementation, AGPL, AgencyDomains.org) with the naming scheme Vergis · Botler · Mira; the **proto-Botlet** added to the cast of primitives (tempered · platform) and the **derivation chain** use-cases → Botlets → proto-Botlets; **Botlet generations** G1/G2/G3 with the reconciliation of two axes; **manifestation** and **temporality** (`discrete`/`continuous`) as Botlet attributes; **generic Botler** (no per-domain subtypes; validates by orchestrating; Layer 2 ↔ Layer 3 interface via `MCP`; source code vs spec; one Botlet per `PI`); correction of the "internal A2A" misnomer (`A2A` reserved for the relation between AgencyDomains); `Capability` reserved for the cognitive know-how of Layer 2, with **Connector** (Layer 4), **Template** (Layer 1), **feature**, and **Capability portability**; **declared bounded interaction** (embedded Facet) and **multi-view `PI` with drill-through**; **declarative quality contract** in Trust Infrastructure.
- **Changes v0.3 vs v0.2**: the agent's three times (Preparation · Attention · Engineering), composition of Layer 1 (shell · view · operation), and the Facet as Layer 1's atomic primitive.
- **Changes v0.2 vs v0.1**: the main title *AgencyDomains* + ten extensions (Botlet maturity, distributed Layer 3, portability, seed/emergent, certification in the Capability, Capability locality, GUI on-the-fly, operational continuity, parallel topology, title).

---

## 1 · Panoramic view

```
                    THE PARADIGM
                          │
                          ▼
              ┌─────────────────────────┐
              │                         │
      The Nadella Line          The Agentive World
      (the question)            (the consequences)
                          │
                          ▼
                THE AGENTIVE ARCHITECTURE
                          │
          ┌───────────────┼───────────────┐
          │               │               │
     4 layers         Trust Infra      Agent First
     (parallel        cross-cutting    (governing principle)
     topology)
                          │
                          ▼
                   THE PRIMITIVES
                          │
   ┌──────────┬───────────┼───────────┬──────────┐
AgencyDomain Botlet    Capability   Trust    Assistant
+ proto-     + Agentlet (Layer 2 ·   Infra    vs Autonomous
Botlet       (Lets:     Connector ·           Agent
(pre-forged) manifest./ Template)             + Facet
             tempor.)
                          │
                          ▼
                   THE MARKET POSITIONING
                   (AI value chain · 11 × 4)
                          │
                          ▼
                   THE APPLICATIONS
                   (Real-time knowledge ·
                    Varnished Kimball · conversational BI)
                          │
                          ▼
                   THE OPERATION
                   (Trust Infra operationalized ·
                    policies · CRUDLEX · log ·
                    operational continuity)
```

**The eight canonical primitives**: **AgencyDomain** · **Botlet** · **proto-Botlet** · **Agentlet** · **Capability** · **Trust Infrastructure** (cross-cutting axis) · **Assistant vs Autonomous Agent** · **Facet**. The **proto-Botlet** is the pre-forged piece the agent configures to instantiate a Botlet; the **Agentlet** is the Botlet's sibling unit with bounded inference; the **Facet** is the atomic primitive of Layer 1.

> **Numbering note**: when the canon labels the Facet as the *sixth primitive*, the proto-Botlet as the *seventh primitive* and the Agentlet as the *eighth primitive*, the ordinal indicates the **order of incorporation into the canon** (Facet in v0.3, proto-Botlet in v0.4, Agentlet in v0.6), **not** the position in this list.

**Pre-agentive layer (BCA)**: cartography of the state *prior* to crossing the Nadella Line. Three layers (Presentation · Business Logic · Domain), seven structural separations (the seventh, canonical: Procedural / Agentic), with explicit mapping of how each cell migrates into the Agentive World.

**Reference implementation**: **Vergis** — the public reference implementation of AgencyDomains (AGPL, AgencyDomains.org), category **Meta-Cognitive Platform**. It materializes the canon in an executable runtime.

---

## 2 · The paradigm — the Nadella Line

### The dividing question

> *Does the human open applications to do their work?*

Origin of the name: Satya Nadella on the BG2 podcast (December 2024) — *"The notion that business applications exist — that's probably where it all collapses, in the era of agents."*

### Two worlds

```
◄──── Agentic World ────┤├──── Agentive World ────►
Apps complemented          Apps collapse
by copilots                Conversation with agents
Incremental evolution      Applications survive
                           as invisible backend
                           Fundamental transformation
```

- **Agentic** — agents are complementary tools that extend existing applications. Humans keep opening applications. Traditional interfaces persist; agents enhance them.
- **Agentive (Agentive World)** — agents as the sole interface. Applications collapse. The human stops opening applications; they converse with agents that have access to systems and data.

### Online enterprise vs Real-time enterprise

- **Online enterprise** — data current to the second, dashboards up to date, but it **depends on humans** to look, interpret, and decide.
- **Real-time enterprise** — it **detects, interprets, decides, and acts** continuously and autonomously, within governed frames. The product of crossing the Nadella Line.

### Three axes of deep change

Crossing the Nadella Line changes **six dimensions** of operation simultaneously (human-information relationship, nature of data, roles of human work, economics of information, governance, operating model). None changes in isolation. Those six dimensions group into **three axes**:

1. **Human-information relationship + roles of human work.**
2. **Data + operating model.**
3. **Governance + economics of information.**

The three are interdependent: advancing in one alone without the others produces **successful pilots but no real transformation**. The crossing is systemic or it is not.

### Evolutionary coexistence

```
Stage 1 (Initial):    Assistant 90%  ████████████████░░  Autonomous Agent 10%
Stage 2 (Adoption):   Assistant 70%  ████████████░░░░░░  Autonomous Agent 30%
Stage 3 (Maturity):   Assistant 50%  █████████░░░░░░░░░  Autonomous Agent 50%
Stage 4 (Advanced):   Assistant 30%  █████░░░░░░░░░░░░░  Autonomous Agent 70%
```

---

## 3 · The pre-agentive state — Bounded Concerns Architecture

> Formal cartography of the state *prior* to the crossing. It is not the architecture of the destination — it is the architecture of the transition.

### Operational principle — the thinness of the domain

Agents are **volatile** (statistical correctness, evolution by retraining). Business invariants **cannot be** (binary correctness, structural cadence). If they coexist in the same layer without an explicit boundary, agentic volatility contaminates the reliability of the domain.

→ **The authoritative core is kept strictly thin**, expelling all volatile logic outward. The agentic incursion is confined to the layer designed to tolerate volatility.

### Three layers

| Layer | Content |
|---|---|
| **1 · Presentation** | UI (humans) · API (systems) — treated as parallel citizens. |
| **2 · Business Logic** | Orchestration. Two parallel boxes: **Procedural** (explicitly programmed) · **Agentic** (contextually derived from a model). |
| **3 · Domain** | Stable core. Two orthogonal dimensions: **SOR** (System of Record, own domain) vs **External** (foreign domain) on the vertical axis; **Logic** vs **Persistence** on the horizontal axis. Each cell subdivides into a synchronous and an asynchronous path. |

Deliberate lexical asymmetry in the asynchronous leg: **Streams** (SOR side — outgoing, own authorship) vs **Hooks** (External side — incoming, foreign authorship).

### The seven structural separations

| # | Separation | Materialized by |
|---|---|---|
| 1 | Human presentation vs external contract | UI and API in Layer 1 |
| 2 | Orchestration vs domain rules | Layer 2 / Layer 3 boundary |
| 3 | Logic vs persistence | Horizontal bands in Layer 3 |
| 4 | Own vs foreign domain | SOR / External columns in Layer 3 |
| 5 | Synchronous vs asynchronous communication | Parallel paths within each cell |
| 6 | Mutable state vs event log | Repository/Streams and Proxies/Hooks pairs |
| 7 | Procedural vs agentic behavior | Procedural / Agentic boxes in Layer 2 |

The **seventh separation** is the initial crack through which the Agentive World enters the enterprise system.

### Mapping of BCA cells to the Agentive World

| BCA cell | Trajectory | Destination |
|---|---|---|
| **UI** | Progressively emptied | Replaced by Layer 1 — Interaction (conversational modalities, GUI on-the-fly, persistent GUI as facade Botlet, signage); the traditional UI survives only in specialized tools with complex surfaces |
| **API** | Persists and intensifies | Becomes a **Connector** within Layer 4 — Access (NOT in Capability) |
| **BL · Procedural** | Contracts | Replaced by Botlets. Only workflows with strict regulatory traceability survive |
| **BL · Agentic** | Expands until it dominates | **Operational seed of the Botlet**. The seventh separation widens until it consumes the layer |
| **SOR · Logic** | Preserved | Invariant logic within the AgencyDomain |
| **SOR · Persistence** | Preserved | Storage layer of the AgencyDomain |
| **External · Logic** | Preserved, repositioned | Federation patterns managed by Trust Infrastructure |
| **External · Persistence** | Preserved | Storage layer of the federation |
| **Events (sync/async SOR)** | Preserved, gain weight | Coordination substrate between Botlets and AgencyDomains |

**Four general patterns of the crossing**:

1. **Layer 3 survives almost intact** — it becomes the substrate of the AgencyDomains.
2. **Layer 2 transforms deeply** — Procedural contracts; Agentic dominates; both become Botlets that compose behavior from Capabilities.
3. **Layer 1 bifurcates asymmetrically** — UI dies; API thrives as a **Connector** (Layer 4).
4. **Trust Infrastructure appears as a new cross-cutting concern** — what in BCA was implicit and scattered is elevated to an explicit cross-cutting layer.

---

## 4 · The architecture — four layers in parallel topology

> **Canonical clarification**: the four layers are an **X-ray of the individual agent** — the four behaviors every agent must exhibit. **They are NOT links in an industrial value chain** nor slots where a product is assigned to each. The industrial chain is treated in Chapter 6 — they are distinct lenses that cross cleanly when kept separate.

### The parallel topology

**Layers 2 (Cognition) and 3 (Autonomy) are parallel paths between Layer 1 and Layer 4, not stages in series.** The numbering 1 → 2 → 3 → 4 has didactic value — Layer 1 is the surface the human meets, Layer 4 is where the system touches the real world — but **it does not describe the order in which operations traverse the system**. An operation enters through Layer 1 and reaches Layer 4 by traversing one of the two paths — or both in different stretches — but never both in mandatory series.

```
                ┌──────────────────────────┐
                │  Layer 1 · Interaction   │
                └────┬───────────────────┬─┘
                     │                   │
                     ▼                   ▼
           ┌─────────────────┐ ┌─────────────────┐
           │  Layer 2        │ │  Layer 3        │
           │  Cognition      │ │  Autonomy       │
           │                 │ │                 │
           │  Conversation   │ │  Botlets        │
           │  New decision   │ │  Stable pattern │
           │  New case       │ │  (95/4/1 cycle) │
           └────────┬────────┘ └────────┬────────┘
                    │                   │
                    ▼                   ▼
                ┌──────────────────────────┐
                │  Layer 4 · Access        │
                │  (Capabilities)          │
                └──────────────────────────┘

         Trust Infrastructure (cross-cutting to all four)

         Interaction 2 ↔ 3 (internal · via `MCP`):
           · Cognition delegates to Botlet (2 → 3)
           · Botlet escalates fallback to Cognition (3 → 2)
           · Cognition observes the Botlets' log (2 ← 3)
```

**Layer 2 ↔ Layer 3 interface via `MCP`**: the **Cognition** (`LLM` agent, Layer 2) commands its muscle memory — the **Botler** (Layer 3 runtime, no agency) — over an **internal** interface within the same AgencyDomain. The natural transport is `MCP`: the Botler exposes `MCP` server(s), the Cognition is the client. **This is NOT `A2A`**: `A2A` (the agent-to-agent relation) is reserved for communication **between distinct AgencyDomains**.

**Regime of each path**:

- **Cognition Path** — slow, costly, decisive. For conversation, new decisions, unanticipated cases.
- **Autonomy Path** — fast, cheap, repetitive. For Botlet execution over stable patterns.

**Five structural consequences** of the parallel topology:

1. **Trivial offline mode** — without network, the Cognition path (cloud) falls; the Autonomy path (edge) stays active. The operation traverses the AgencyDomain by whichever path stays alive.
2. **Evident cognitive economics** — the organization chooses which path each operation flows through: repetitive → path 3 (cheap); new or decisive → path 2 (costly). Total cost is the mix of the two paths.
3. **Trust Infrastructure is exercised on both paths** — policies apply before invoking Layer 4 regardless of which path the invocation comes from.
4. **It distinguishes two kinds of Botlets** — **operational facade Botlets** (invocable from Layer 1, stable contract, propagated human identity) vs **internal tool Botlets** (invocable only from Layer 2). Both live in Layer 3; they differ in their invocation surface.
5. **`Layer 1 → Layer 3 → Layer 4` is a canonical path** — an operational surface (POS, kitchen screen, industrial panel) that invokes a senior Botlet traverses this path without touching Layer 2. **It is not a bypass; it is one of the two structural paths.**

### The agent's three times

The parallel topology describes **where** each operation lives. The three times describe **when** the agent operates. A canonical temporal frame, complementary to the spatial one.

| Time | Regime | Metrics | Cognitive path |
|---|---|---|---|
| **Preparation** | Batch · off-peak | Catalog quality · Botlet precision · Capability coverage | Cognition over consolidated data |
| **Attention** | Real time · priority | Satisfaction · latency · resolution rate without escalation | Cognition + Autonomy per pattern |
| **Engineering** | Medium term (minutes to hours) | Coverage · first-deploy success rate · average iterations | Cognition decides · Autonomy persists |

**Operational implications**:
- **Scheduling of cognitive capacity**: Attention is priority; Preparation uses the valleys; Engineering is intermediate. Without the distinction, Preparation is relegated and the agent stops improving itself.
- **Metrics separated by time**: a single dashboard lies; catalog quality is measured differently from operational satisfaction.
- **Availability model**: a well-operated agent is **not 100% in Attention** — it needs Preparation windows. The promise "always-available agent" is understood as "Attention always available".

> *The agent does not attend at every moment — but it can attend at any moment because it dedicates time to preparing.*

**Required properties**:
- Explicit recognition of the three times in operation (MUST).
- Metrics separated by time (MUST).
- Reserved, not optional, Preparation windows (SHOULD).
- Scheduling of cognitive capacity by time priority (SHOULD).
- Traceability in the log of which time executed which operation (SHOULD).

### Structural diagram — all layers with parallel topology

```
                ┌──────────────────────────────────────────────────────────┐
                │  LAYER 1 · INTERACTION                                   │
                │  Pure conversational · GUI on-the-fly · persistent GUI    │
                │  (facade Botlets) · Voice · API · Channels · Signage      │
                └────┬─────────────────────────────────────────────────┬───┘
                     │                                                 │
                     ▼                                                 ▼
       ┌────────────────────────────┐               ┌────────────────────────────┐
       │  LAYER 2 · COGNITION       │               │  LAYER 3 · AUTONOMY        │
       │  Multi-LLM · Capabilities  │               │  Botlets and Agentlets     │
       │  Pattern Recognition       │  ◄── 2 ↔ 3 ──►│  Botler (central + edge)   │
       │  Botlet generation         │               │  Asynchronous tasks        │
       │  Reactive assistant        │  ◄── `MCP` ──►│  Monitoring · A2A protocol │
       │  Slow · costly · new       │   internal    │  Fallback guarantee        │
       └─────────────┬──────────────┘               └─────────────┬──────────────┘
                     │                                             │
                     ▼                                             ▼
                ┌──────────────────────────────────────────────────────────┐
                │  LAYER 4 · ACCESS                                        │
                │  Tools (MCP) · A2A between AgencyDomains · CRUDLEX       │
                │  Human approval · Append-only log · Routing              │
                │  Semantic cache · Connectors                            │
                │  (cloud · edge · hybrid)                                │
                └──────────────────────────────────────────────────────────┘

   ═══════════════════════════════════════════════════════════════════════
   TRUST INFRASTRUCTURE — cross-cutting to all four layers
   Governance · Audit · Validation · Resilience · Transparency

   GOVERNING PRINCIPLE — Agent First
```

### Layer 1 — Interaction (with three GUI regimes)

Responsible for all communication between humans and the system. Pure interface, no business logic.

**Six canonical modalities** (the **generated GUI** is a single modality with three generation regimes):

- **Textual conversational** — direct chat; the agent answers in text. Sufficient when the information is sequential and the decision is flexible.
- **Voice conversational** — virtual assistants, calls, audio bots.
- **Corporate channels** — Slack, Teams, WhatsApp, email.
- **Programmatic API** — machine-to-machine invocation without human mediation.
- **Generated GUI** — graphical surface generated by the cognition (never by a human UI/UX team), in three regimes: **(1) pure conversational** — no surface, when none is needed; **(2) on-the-fly** — adapted to the immediate task, lives as long as the task lasts, may regenerate differently next time; **(3) persistent as a facade Botlet** — for repetitive operational roles (cashier at peak hour, kitchen panel, register dashboard, industrial panel), a stable surface consolidated as a **facade Botlet** — a Layer 3 Botlet (typically seed) that exposes it in Layer 1 —, which the agent regenerates when the environment changes.
- **Passive signage** — surfaces that communicate continuously without requiring interaction.

> *The GUI does not disappear in the Agentive World. What disappears is the pre-created GUI. Every GUI in an agentive Layer 1 is generated by the cognition — some ephemeral, others stabilized as facade Botlets.*

**Layer 1 calibration**: the question is not whether there is a GUI or how pretty it is. The question is **who generated it**. If a human UI/UX team generated it in traditional application sprints, it is not an agentive Layer 1. If the cognition generated it — ephemeral or persistent as a Botlet — it is.

**Three required properties (MUST)**:
1. **Channel-agnostic** — the conversation logic does not depend on the medium.
2. **Register adaptation** — the agent understands the channel's register without conditional code.
3. **Context persistence** — the conversation survives a channel change.

#### Surface composition · shell, view, operation

A non-trivial surface **is not a monolithic Botlet**. It is a composition of three kinds of Botlets in distinct roles:

| Role | Layer | Nature | Reuse |
|---|---|---|---|
| **Surface Botlet (shell)** | Layer 1 | Container: layout · navigation · session · shared state | Product-specific (little reuse) |
| **View Botlet** | Layer 1 | A screen or panel within the shell · assembles Facets + orchestration | Highly reusable across shells |
| **Operation Botlet** | Layer 3 | Business execution (charge, print, close shift, consolidate) | Most reusable in the catalog · stable contract |

**Key distinction**: shell and view are surface (Layer 1); operation is execution (Layer 3). A surface is a composition of Layer 1 Botlets that orchestrate and invoke Layer 3 Botlets.

```
Layer 1: SHELL → VIEW(s) ─── invokes ───▶ Layer 3: OPERATION(s)
```

Operations accumulate durable architectural value; reusable views are extracted and cataloged; shells remain specific but their construction accelerates by assembling existing pieces.

#### Multi-view Information Product · drill-through

An **Information Product (`PI`)** — the manifestation an informational operation Botlet leaves when consumed — is not necessarily a single piece. It can be composed of **N named pieces/pages**: each **view** is one more piece of the same `PI`, selectable from a picker, with the first as default. The `PI` remains **authz-blind** — neither the views nor the edges connecting them declare authorization; that policy lives in the policy store.

**Drill-through** is the **navigation edge with context**: a table/column declares *"on clicking a row, go to view X passing the key K of this row"*; the destination view renders **filtered by K**.

**Data-anchored / no-bypass (MUST)**: the context `K` **bounds within what the viewer can already see** — the destination view applies its own `RLS` over the source and `K` enters as an additional filter, **never as an override** of the policy. The drill **narrows, never widens** (intersection with the authorized, never union). If the viewer cannot reach the origin row, they do not reach the edge; if they reach it, the destination is still governed by its own policy. Multi-view composition is orthogonal to the Botlet's family: it changes how many pieces compose the manifestation, not its nature.

#### Facet · atomic primitive of Layer 1

The **Facet** is the atomic reusable component of Layer 1: drawing board, catalog-picker, color matrix, calendar, clickable map, slider, drag-and-drop. **Sixth canonical primitive** — distinct from the Botlet (described fully in §7).

**A Facet is NOT a Botlet**:
- A Facet lives in Layer 1 (Interaction) · a Botlet lives in Layer 3 (Autonomy).
- A Facet is an **instrument** the cognition invokes during conversation · a Botlet is **muscle memory** that executes without cognition.
- A Facet has NO fallback guarantee · a Botlet DOES.
- A Facet is ephemeral · a Botlet is persistent.

**Agentive behavior**: the agent **estimates in real time** whether the information is best obtained verbally or visually. If the visual path wins, it offers a Facet. Heuristics: high dimensionality → Facet; low dimensionality → conversation; hard to verbalize (color, position, shape) → Facet; the user already has it in visual form → Facet.

### Layer 2 — Cognition

The agent's brain. Interpretation, reasoning, planning, application of specialized knowledge, the decision to delegate.

**Five canonical components**:
1. **Multi-LLM** — the cognition is not tied to a single provider.
2. **Capabilities** — units of modular, composable cognitive know-how (reserved to this layer).
3. **Pattern Recognition** — detection of repetitive patterns. Inspired by neurobiological architecture. Trigger of emergent Botlet generation.
4. **Botlet generation** — the cognition decides when to delegate repetitive tasks to Layer 3.
5. **Reactive assistant** — agent operating in request-response mode.

**`Capability` reserved for the cognitive know-how of Layer 2**: a **Capability** is **cognitive**, interpretive, decisional know-how. **It is NOT a plugin, NOT a prompt, NOT a system prompt, NOT a tool — it is knowledge.** The Capability decides which tool to invoke. Two analogous terms live in other layers and are named for what they are, without appending the term Capability:

- **Connector** — knowing how **to access source systems** (a connection with execution power; NOT cognitive knowledge). **Layer 4 · Access.** In the legacy→agentive map, an **API** becomes a **Connector** (Layer 4), not a Capability.
- **Template** — client-specific tailoring over a **canonical instrument** (report/dashboard) in a particular format or rule. **Layer 1 · Interaction**, alongside Facets and surface/view Botlets.

**feature** — an internal operation a Capability exposes (the practical equivalent of *feature/operation/skill/method*). **Capability vs feature test** (all three must be yes to treat it as its own Capability): (1) operational independence? (2) cognitive identity — distinct data model and SME? (3) reusability? If one or more is no → it is a **feature** of the containing Capability.

**Capability vs non-Capability test** (all three yes → Capability): (1) is it cognitive know-how? (2) does it have an identifiable SME? (3) does it pass the five Wingtraining steps without forcing? If not: access to systems → **Connector** (Layer 4); tailoring of a canonical instrument → **Template** (Layer 1); operation within a larger Capability → **feature**.

**Capability portability (MUST)**: a conformant Capability can be installed and run on **any conformant AgencyDomain** without rewriting, which makes it **real property of the client** — not of the AgencyDomain nor of the hosting. Relationship: an AgencyDomain **hosts and runs** Capabilities; a Capability **runs on** a host AgencyDomain. Distinct from AgencyDomain portability (across hosting platforms).

**Two modes of access to cognition**:
- **Tokens** — the system centralizes credentials, billing, and policies.
- **Subscription** — the user's assistant (Claude, ChatGPT, Copilot, Gemini) accesses directly under the user's subscription.

Both modes coexist. The spec requires explicitly declaring which mode applies to which component.

**Botlets as economic lever under a fixed Subscription**: on capped plans, an agent that executes via Botlets and invokes cognition only when the environment changes operates continuously without exhausting the quota. Without Botlets, sustained autonomy under a fixed Subscription is economically impossible.

**BYOModel (SHOULD)** — Bring Your Own Model. The agent's spec MUST be independent of the cognition runtime. It enables multi-tenancy with heterogeneous cognition and respects the client's **cognitive sovereignty**.

### Layer 3 — Autonomy (with distributed Layer 3)

Where the agent lives. Persistent life, continuous execution, action on its own initiative. Where the **Autonomous Agents** dwell.

**Six canonical components**:
- **Proactive processing**, **asynchronous tasks**, **continuous monitoring**.
- **Lets in execution** — two sibling species: **Botlets** (muscle memory, non-LLM code) and **Agentlets** (packaged routine judgment, bounded inference; §7).
- **Botler** — generic runtime that executes the Lets of both species. Invisible. **1 Process = 1 Botler + N Lets**.
- **Intra-AgencyDomain coordination (via the `A2A` protocol)** — communication between runtimes of the same agent. It is NOT `A2A` between AgencyDomains.

**Non-negotiable property — Fallback guarantee (MUST)**: if a Botlet fails catastrophically, the cognition executes the task manually. **The process never stops.**

**Three required properties (MUST)**:
1. **Persistence between sessions**.
2. **Execution isolation** — Lets (Botlets and Agentlets) under sandboxing.
3. **Structural resilience**.

**The Botler is generic by definition (MUST)**: it manages the lifecycle, isolation, and execution of *any* Botlet **without understanding its domain**. **No Botler subtypes exist by family of operation** (informational, transactional, etc.) — that specialization lives in the Botlets and their proto-Botlets. Botler subtypes are distinguished by **deployment topology and role** (central/edge; operational facade), **never by domain**. A flat architecture: a generic runtime hosts self-contained specialist components.

**The Botler validates by orchestrating, not by executing (MUST)**: it enforces the spec's validation against the Botlet's type without executing it with domain knowledge. It invokes the validation point the type (or its proto-Botlet in G1) provides, hands it the **generic context** it controls (Capability catalog, identity, AgencyDomain policies), and acts on the verdict — accept, reject, record in the append-only log. Sibling pattern: on each invocation the Botler hands the Botlet a **controlled handle** (an object with `capability_call` and `log` bound to the Botler); bypass is **structurally impossible**, not merely forbidden. Principle: the generic Botler exposes **control points** and the specialist plugs into them.

**Distributed Layer 3** (canonical pattern for multiple physical presence): a single AgencyDomain with a **central Botler** (cloud, orchestration, consolidated DB) + **N edge Botlers** (one per physical site, local DB, queue toward central), coordinated by **the `A2A` protocol** (intra-AgencyDomain coordination). Distinct from federation between AgencyDomains; distinct from a simple Cluster. Full detail in §7 (Primitives).

### Layer 4 — Access

Where cognition becomes real action. Every decision MUST pass through governance before touching the world.

**Eight canonical components**:
- **Tool servers** — canonical protocol **MCP**.
- **Connectors** — knowing how to access source systems (the legacy API brought into the Agentive World).
- **`A2A` between AgencyDomains** — federation between distinct agents.
- **Trust Infrastructure exercised at the point of action**.
- **CRUDLEX** — Create, Read, Update, Delete, List, Execute.
- **Human approval**.
- **Intelligent routing and semantic cache**.
- **Immutable append-only log**.

**Four MUST properties in enterprise production**:
1. **Non-repudiation** — every action recorded with identity, context, and result.
2. **Reversibility where applicable**.
3. **Policy before execution** — policy is evaluated **before**, not after.
4. **Uniform observability**.

---

## 5 · Trust Infrastructure — the cross-cutting axis

**It is not an additional layer. It is cross-cutting to all four.**

### Five pillars

| Pillar | Canonical mechanisms | Primary layers |
|---|---|---|
| **Governance** | Configurable policies · CRUDLEX · human approval · AI registry | Layer 4 (primary), cross-cutting |
| **Audit** | Append-only log · trace of each action · decision lineage · per-action identity tagging | Layer 4 (primary), cross-cutting |
| **Validation** | Hallucination detection · response validation · prompt injection prevention · DLP · tokenization | Layer 2 (partial) + Layer 3 (Agentlets' bounded inference) + Layer 4 (primary) |
| **Resilience** | Fallback guarantee · error handling · sandboxing · circuit breakers · rate limiting | Layer 3 (primary), cross-cutting |
| **Transparency** | Full observability · metrics · end-to-end traces · proactive alerts · governance dashboards | Cross-cutting to all four |

### Pillar × layer matrix

```
                    Layer 1        Layer 2        Layer 3        Layer 4
                    Interaction    Cognition      Autonomy       Access

Governance                                                       ████████ (primary)
Audit                                                            ████████ (primary)
Validation                         ████ (partial)                ████████ (primary)
Resilience                                        ████████ (primary)
Transparency        ────────────────────── cross-cutting ──────────────────
```

### Tripartite deployment pattern — Cloud + Client + Local

Three components coordinated in physically distinct places: **Cloud** (the provider's control plane), **Client** (governance plane in the client's internal network), **Local** (execution plane on the user's device).

### Declarative quality contract

Any conformant Botlet MAY declare its quality attributes as **structured properties, not embedded code**, so Trust Infrastructure audits them uniformly, routes them through global policies, and reports them as standard metrics without coupling to each Botlet's implementation. Five canonical attributes:

- **Freshness** — maximum admissible age of the data.
- **SLA** — expected end-to-end latency (`p50`/`p99`).
- **Degradation policy** — `refuse` · `warn_and_show` · `show_last_valid` · `agentic_fallback`.
- **Audience** — `RLS`/`CRUDLEX` policy of who may consume the manifestation.
- **Refresh policy** — `on-demand` · `scheduled` · `push`.

It serves two pillars: **Resilience** reads degradation and refresh as auditable configuration (not fragile scattered logic), with Freshness and SLA as explicit thresholds; **Audit** routes them through global policies and reports them as metrics comparable across Botlets.

---

## 6 · The governing principle — Agent First

> *Faced with any trade-off, the agent's experience is prioritized over the human's. The agent is the primary user; the human's needs are resolved in a management layer without degrading what the agent sees and can do.*

### Operational implications

- Any new capability is specified first as a **tool with a declarative JSON schema**.
- **Structured, actionable errors**.
- **Idempotency where applicable**.
- **Uniform pagination and filters** across tools.
- **Machine-readable documentation**.

Agent First is a **governing rule**: any trade-off that violates it requires explicit, documented justification.

---

## 7 · The primitives

### AgencyDomain

A computational scope with its own identity where autonomous agents and Botlets in execution dwell, **where the Capabilities that give them their know-how are hosted and run**, and where the resources that sustain them live. **Minimal unit of deployment.** The Capability is a first-order inhabitant, not a support resource.

**Foundational premise — Space ≠ Domain**:
- **Space** / **WorkSpace** (Google Workspace, M365, Notion) — human corporeality. Reserved for humans.
- **Domain (AgencyDomain)** — the agent has no body; it has jurisdiction (`dominium`).

Formal lineage: just as **JavaSpaces (JSR-000148, 1999)** standardized distributed spaces for Java without binding the implementation, **AgencyDomains** does the equivalent for agentive environments.

#### Five fundamental properties (MUST — a system that does not meet them is not an AgencyDomain, it is something else with another name)

1. **Own identity** — a unique canonical URI that distinguishes it on any network; survives restart, migration across infrastructures, and change of implementation. Stable, not ephemeral.
2. **Materialization of the four layers** — it materializes Interaction · Cognition · Autonomy · Access and exercises cross-cutting Trust Infrastructure. The layers may be distributed technically, but responsibility for the four rests with the space. No conformant space delivers only three nor delegates a layer without assuming responsibility.
3. **Persistence** — the state (active agents, Botlets in execution, Capability data, audit logs) survives disconnections, restarts, and migrations. It is what makes the AgencyDomain a **place**, not a process.
4. **Isolation** — an explicit boundary; internal resources (compute, memory, data) are not accessible from outside except through defined interfaces (via Layer 4, registered). Not only security: it is **fault containment** — an AgencyDomain that falls does not affect others sharing infrastructure.
5. **Addressability** — AgencyDomain, agents, and Botlets addressable via predictable URLs. Canonical syntax:

```
{domain}/                                  → the space itself
{domain}/agents/{agent}                     → an agent that lives in it
{domain}/agents/{agent}/botlets/{botlet}    → a specific Botlet
{domain}/tools/{tool}                       → a tool exposed via Layer 4
```

Addressability sustains two things: `A2A` (an agent invokes another by its canonical URL, without ad hoc discovery) and **MEO** (frontier models reference AgencyDomains via predictable URLs that appear in their training corpus). Chaotic or unstable URLs → an AgencyDomain invisible to the models.

#### Canonical data model — six spec components

Internal anatomy of a conformant AgencyDomain:

1. **Identity** — canonical URI, credentials with which it authenticates against external systems, root policies no agent may contravene.
2. **Agents** — collection of the space's agents; each with its assigned Capabilities, its Botlets in execution, and its persistent state.
3. **Capabilities Registry** — tree of Capabilities available to the space's agents (shared know-how, invocable by role).
4. **Tools Registry** — collection of tools that Layer 4 exposes outward (the interface through which the AgencyDomain touches external systems).
5. **Trust Layer** — cross-cutting governance and audit: policies, append-only log, validation mechanisms.
6. **Cognition Bindings** — bindings to the cognitive resource: which model provider is invoked, under what credentials, and with what usage policies.

#### Three regimes (technically equivalent; the regime changes, not the capability)

```
Private   = controlled perimeter, no public access     (analogous to Private Cloud)
Public    = externally accessible, registered agents   (analogous to Public Cloud)
Hybrid    = private core + partial public exposure     (analogous to Hybrid Cloud)
```

**Natural migration between regimes without rewriting.**

#### Distributed Layer 3 — canonical pattern for multiple physical presence

A single AgencyDomain with Layer 3 distributed geographically: a **central Botler** (cloud, orchestration, planning, reporting, global decisions, consolidated DB) + **N edge Botlers** (one per physical site, local transactional Botlets, local DB + event queue toward central), coordinated by **the `A2A` protocol** (intra-AgencyDomain coordination between runtimes of the same agent — not `A2A` between AgencyDomains).

```
                        ┌────────────────────────┐
                        │   CENTRAL Botler       │
                        │   (cloud)              │
                        └────────┬───────────────┘
                                 │ A2A protocol
                  ┌──────────────┼──────────────┐
                  ▼              ▼              ▼
          ┌─────────────┐ ┌─────────────┐ ┌─────────────┐
          │ EDGE Botler │ │ EDGE Botler │ │ EDGE Botler │
          │ (site 1)    │ │ (site 2)    │ │ (site N)    │
          └─────────────┘ └─────────────┘ └─────────────┘

         All within the same AgencyDomain
         (single identity · single log · single governance)
```

**Offline mode as an emergent property**: when the edge Botlets are **senior**, the physical site operates against the local DB + edge-resident Connectors without network. The event queue toward central accumulates transactions; when the network returns, it drains.

**Required properties**:
- Single identity of the AgencyDomain (MUST)
- Single internal identity model (MUST) — the Botlers do not authenticate as external AgencyDomains to each other; they share the AgencyDomain's identity model.
- Local DB in each edge Botler (MUST)
- Event queue toward central (MUST)
- Conflict resolution on consolidation (MUST)
- Unified audit log (MUST)
- Uniform Trust regime between central and edge (MUST)
- Offline operation capability at the edge (SHOULD) — when the edge Botlets are senior, the site operates with intermittent network or none.

#### Portability between conformant platforms

A conformant AgencyDomain **MUST** be migratable to another **conformant hosting platform** without rewriting its logic, its state, or its policies. Distinct from migration between regimes (private → public), which changes the regime but not the platform.

**Three technical conditions**:
1. **Botlets against the canonical primitives** of the conformant SDK, not proprietary APIs of the current hosting.
2. **Exportable operational DB** in a reproducible neutral format (documented schema, complete dump, no proprietary types).
3. **Portable Trust Layer** — policies, log, and configuration in a format readable by any conformant implementation.

It guarantees that the AgencyDomain is **real property of the client**, not of the hosting.

#### Account vs AgencyDomain · Domain vs AgencyDomain · Dominion · Cluster vs Federation

- **Account** — a commercial concept; it may own multiple AgencyDomains.
- **Domain** — commercial synonym for AgencyDomain (brand lore, sales, client communication).
- **Dominion** — a Domain obtained by an agent in a public AgencyDomain under the **AgentNation** model.
- **Cluster** — instances of the **same** AgencyDomain sharing load.
- **Federation** — communication between **distinct** AgencyDomains.

#### Agent lifecycle — six canonical phases (each transition → append-only log of the Trust Layer)

1. **Provisioning** — the AgencyDomain creates the agent: assigns identity, associates the initial Capabilities, registers it in the space. It is born when the phase ends successfully; if it fails (credentials, name conflict, quota), it never comes to exist.
2. **Bootstrap** — it enters operation: loads its persistent state if it exists (recovers context after hibernation or restart), establishes bindings with cognition and tools, verifies Capability availability.
3. **Reactive operation** — Assistant mode, Layer 2 active. Responds to the human's requests; between requests it stays passive (no active compute).
4. **Proactive operation** — Autonomous Agent mode, Layer 3 active. Pursues objectives in the background, monitors events, executes Botlets, escalates to the human at thresholds; Pattern Recognition generates and maintains Botlets. Materializes *"intelligence goes to people and acts on their behalf"*.
5. **Hibernation** — persistent pause: state saved, no active compute. Preserves context without spending resources (e.g., an agent that hibernates outside business hours and reactivates the next day).
6. **Decommissioning** — the AgencyDomain retires the agent: state archived or deleted per policy, Capabilities released, identity recorded in the historical log. It formally closes the cycle — "decommissioned" ≠ "forgotten": the record allows auditable reconstruction that the agent existed, what it did, and why it ceased to exist.

#### Communication · Layer 2 ↔ Layer 3 interface vs `A2A`

`A2A` (`agent-to-agent`) is a name reserved for the **relation between distinct AgencyDomains** — distinct agents, each with identity and agency; federation, open work.

- **Layer 2 → Layer 3 interface via `MCP`** — the Cognition commands the Botler (its muscle memory) within the same AgencyDomain. The Botler exposes `MCP` server(s); the Cognition is the client. **It is NOT `A2A`.**
- **Intra-AgencyDomain coordination (via the `A2A` protocol)** — the transport between Botlers of the same AgencyDomain uses **the `A2A` protocol** (the protocol's proper name). One says "via the `A2A` protocol", **never "internal A2A"** — those Botlers are runtimes of the same agent, not two agents.
- **`A2A` between AgencyDomains** — between agents that live in distinct AgencyDomains; it requires discovery, cross-authentication, and semantic resolution. Open spec at v1.0.

### Botlet

**Self-evolving automation unit.** Traditional (non-LLM) code generated by an agent. **Muscle memory.**

#### Canonical 95/4/1 cycle

95% normal execution, 4% detected change, 1% regeneration.

**Fallback guarantee (MUST)**: if the Botlet fails catastrophically, the cognition executes manually.

**Botler** — generic runtime (without understanding the domain) that executes the layer's Lets: Botlets and Agentlets. **1 Process = 1 Botler + N Lets**.

#### Botlet maturity — junior, learning, senior

The `95/4/1` cycle describes the steady state; Botlets transit through phases with distinct proportions:

| Phase | Typical proportion | Behavior |
|---|---|---|
| **Junior** | `60 / 35 / 5` | Just generated. Knows the environment only in the version observed at creation. Depends heavily on cognition. |
| **Learning** | `85 / 12 / 3` | Has gone through its first invocations, was regenerated several times, incorporated variants. Operates with intermittent network. |
| **Senior** | `99+ / <1 / ~0` | Incorporated the environment's variants. **Its only failure modes are exogenous** (power, hardware, catastrophic network) — not pending learning. **Reliably operable offline**. |

**Three implications**:
1. Reliable offline operation is a property of **senior** Botlets, not Botlets in general.
2. The **agentic fallback guarantee is what produces maturity**. Each Botlet failure activates the cognition; each activation regenerates incorporating the variant. **Without agentic fallback, the Botlet does not mature.**
3. Maturity is **traceable** in the append-only log.

#### Seed Botlets vs emergent Botlets

Two canonical origins of the Botlet:

- **Seed Botlet** — generated by the cognition at the **design team's** request, as part of the initial product. The decision to exist is the design's, not Pattern Recognition's. **Persistent GUIs generated as facade Botlets** are seed facade Botlets — Layer 3 Botlets whose stable surface lives in Layer 1.
- **Emergent Botlet** — generated by **Pattern Recognition** during operation, when the cognition detects an unanticipated repetitive pattern.

Both live and operate identically once generated. The difference is in the origin. A productive agentive system **does not need to wait for Pattern Recognition** to discover critical Botlets — the seeds are generated at the start per the product spec.

#### proto-Botlet — the pre-forged piece

A **proto-Botlet** is a pre-forged piece of operational capability that the agent, in its **Engineering** time, **configures** to instantiate a Botlet specific to the case. The proto-Botlet contains the code; the Botlet is the configured instance. A generic → instance relation: the proto-Botlet lives in a catalog and serves many cases. It is added to the cast of canonical primitives.

**Two classes**:

| Class | What is its code? | How is it configured? |
|---|---|---|
| **Tempered** | Code specific to its function (e.g., `account-charge`, `esc-pos-printer-command`) | Bounded parameterization |
| **Platform** | Generic code (an engine) whose specialization lives in compositional configuration (e.g., `Mira`) | Compositional configuration; covers N functions of the domain |

Different implementations maintain **proto-Botlet catalogs** — public at AgencyDomains.org, private in proprietary codices. The degree to which the agent configures, co-writes, or generates the code defines the **Botlet generations** (§11).

#### Derivation chain

```
Documented use cases
     │ each case requires
     ▼
Required Botlets  (zero, one, or several; some the cognition resolves without a Botlet)
     │ each Botlet is an instance of
     ▼
Required proto-Botlets from the catalog
```

Required structural property: every conformant Botlet **MUST** be traceable along this chain; the append-only log **MUST** record the origin proto-Botlet of each instantiated Botlet. The *method* of Discovery does not rise to the canon; only the structural relation and its traceability.

**Common catalog and network effects**: proto-Botlets accumulate in catalogs shared by communities of implementers; each consumer contributes to maturation (variants, tested configurations, refinements); implementer n+1 receives versions refined by implementers 1..n. Four membership modes: **private contract** · **proprietary codex** · **open public catalog** (AgencyDomains.org) · **sovereign agreement**.

#### Manifestation and temporality

**Manifestation** — the actualization of the Botlet's latent disposition in the world, perceptible or not (potency → act). **It is NOT "appearance"**: a Botlet that fires a periodic ingestion manifests even if it leaves no visible artifact. It is the abstract genus; each family specializes it: **information** → leaves an **Information Product (`PI`)**; **action** → an effect on the world; **decision** → per its practice. The `PI` is **not a canon primitive** — it lives in the practice of information, one level more concrete.

**Temporality** — the regime of the manifestation. A declared attribute, two values:

| Temporality | How does it manifest? | Runtime |
|---|---|---|
| **`discrete`** | In pulses: wakes on schedule/trigger/event, acts, rests | The Botler invokes or schedules; the Botlet does not live between pulses |
| **`continuous`** | Sustained: lives persistently | The Botler sustains execution while the Botlet lives |

`temporality: continuous` ⟺ persistent Layer 3 life (MUST: a persistent runtime that sustains it). **"Real time" is not chosen on a delivery channel** (`push`); it is chosen by giving the Botlet **continuous temporality**, which mandates the persistent runtime. It connects with *Online enterprise ≠ Real-time enterprise*: points on the temporality continuum. A report (snapshot) and a live dashboard are the **same manifestation under different temporality** → a single runtime (one builds the continuous case; the simple ones are degenerate configurations).

#### Source code vs spec · two surfaces · one Botlet per `PI`

**Source code** (below) = the implementation; for a platform proto-Botlet = the **engine**, shared by all its Botlets. **Spec** (above) = specializes the behavior to the instance; it is not the code, it configures it.

| Surface | What does it manage? | Granularity | Cadence |
|---|---|---|---|
| **Source code lifecycle** | Install/version/load/unload the engine | Botler-level | Releases (Product) |
| **Operation** (includes configuring the spec) | Specialize/manifest/consume/control each Botlet | Per-Botlet | Fluid (Instance) |

**Configuring the spec is operating**: for a platform Botlet the spec is the operational input. The agent evolves the spec **by operating** (verb `specialize`); **crystallization** into a versioned registry **follows, it does not precede**; provenance is given by the append-log. **Verbs of the operation API**: `specialize` · `invoke`/`schedule` (discrete) · `read`/`subscribe` (continuous) · `status`/`activate`/`deactivate`/`retire`.

**One Botlet per `PI`** over a shared engine: each Information Product is its own Botlet/service — with its own `identity`, temporality, maturity, and fallback —, specialized from the shared engine (platform proto-Botlet). Not one Botlet with N configs; not N programs. It is `1 Process = 1 Botler + N Botlets` with the Botlets as specialized instances of the same proto-Botlet. **RISC** rationale: many simple, focused Botlets compose better than a monolith. The `subscribe` consumption is the bridge to the **agentive north** — today a human consumes it (`SSE` in the browser), tomorrow the Cognition.

### Agentlet · eighth canonical primitive

**Packaged unit of Layer 3, sibling of the Botlet, whose execution body invokes bounded inference** — a model sized to the task, within a charter declared in the spec. The canonical home of the task **recurrent in form but interpretive in every instance** (classify, triage, summarize, extract, judge): stable pattern, fresh judgment on every execution, with no possible convergence to determinism. An instance of a **proto-Agentlet** (same tempered · platform classes); hosted by the Botler; engendered and maintained by the agent.

> *The Botlet is muscle memory. The Agentlet is packaged routine judgment. Cognition is reserved for the genuinely new.*

**The genus has a proper name — the Lets**: the Botler hosts **Lets** — Botlets and Agentlets, its two species. The name derives from the family's `-let` suffix; normed vocabulary (like Botler), not a ninth primitive; descriptively, the packaged unit of Layer 3. The shared apparatus is predicated of the genus (proto-/instance, catalogs and network effects, spec vs source code, manifestation, temporality, declarative quality contract, derivation chain, append-only log, operation verbs); the differential guarantees, of each species. Canonical relation: **1 Process = 1 Botler + N Lets**.

**Agentlet vs Botlet** (the differential; everything else is identical by genus):

| Axis | **Botlet** | **Agentlet** |
|---|---|---|
| Body | Non-LLM code; zero inference | Bounded inference via the Botler's handle |
| Natural task | Recurrent, **crystallizable** into code | Recurrent in form, **interpretive** in every instance |
| Determinism | Converges with maturity | Does not converge — statistical correctness by nature |
| Marginal cost | ~0 | Tokens per execution, budgeted in the spec |
| Maturity | Junior → senior (exogenous-only failures) | Spec stabilization + decreasing escalation rate |
| Offline | Senior operable offline | Only with an edge-resident model, **declared** (MUST) |
| Fallback | Cognition executes manually | Escalates to **full Cognition** |

**Smuggling rule (bidirectional, MUST)**: if there is inference in the body, it is an Agentlet — a Botlet with a hidden `llm_call` is non-conformant. If there is none, it is a Botlet — an Agentlet resolvable with deterministic code is **crystallized** into a Botlet. The mature system migrates work down the ladder: Cognition → Agentlets → Botlets.

**Agentlet vs Agent — agenda vs charter**: the **Agent** umbrella covers three members — Assistant · Autonomous Agent · **Agentlet**. **The Agent has an agenda; the Agentlet has a charter**: its inference is spent on *how* to do its own work, never on deciding *what* its work is. Border test (any "yes" on the autonomy side → it is an Agent, not an Agentlet): (1) does it choose its own goals or receive them declared in the spec? (2) can it alter its process or engender other units? (3) is its identity that of an inhabitant (provisioning) or an instance (`specialize`)?

| Axis | **Autonomous Agent** | **Agentlet** |
|---|---|---|
| Nature | **Inhabitant** of the AgencyDomain | **Catalog piece** (instance of a proto) |
| Born through | Provisioning (six phases) | `specialize` over a proto-Agentlet |
| Agenda | Pursues goals; decides what to do | Fixed charter declared in the spec |
| Cognition | Full (bindings, complete tree, multi-LLM) | Bounded (sized model, the spec's Capabilities) |
| Engenders | Generates and regenerates Botlets and Agentlets | Engenders nothing; it is maintained |
| Fallback | *Is* the fallback (above it, only the human) | Escalates to Cognition via the Botler |
| Governance | Exercises the five pillars (MUST) | Control points of the Botler's handle |

**The Botler as sole guardian (MUST)**: the Agentlet brings no runtime of its own. The controlled handle gains a third control point — **`cognition_call`** — alongside `capability_call` and `log`: the body's only path to a model. All of its inference is thus metered, budgeted, **validated** (Pillar 3 gains a seat in Layer 3) and audited in the same append-only log. Segregation by resource profile is a deployment role (pools), never a parallel runtime per species. The two relations cover both species equally: the **agent** engenders and maintains (parent); the **Botler** hosts and executes (butler).

**Three-rung economics**: Botlet (zero inference, ~0 cost) · Agentlet (bounded inference, budgetable per Let) · Cognition (full, for the new). The Autonomy Path remains the cheap one, but stops being uniformly free: the mix is declared per unit. Under fixed Subscription, Agentlets consume quota — bounded and visible in the log —; their share of the mix is an explicit economic decision.

**Required properties**: declared charter — task, inputs, outputs, limits (MUST) · declared bounded inference — model, Capabilities, budget (MUST) · all inference via `cognition_call` (MUST) · fallback to full Cognition (MUST) · zero inference outside the handle (MUST) · hosting by the generic Botler, no parallel runtime (MUST) · traceability of every execution and inference call in the log (MUST) · traceable in the derivation chain with the proto-Agentlet recorded (MUST) · declared locality of the bounded cognition and offline behavior (MUST) · Pillar 3 Validation at the control point (MUST) · Agentlet vs Autonomous Agent distinction in API and documentation (MUST) · maturity metrics of its own (SHOULD) · crystallization into Botlets (SHOULD) · pool segregated by resource profile (MAY).

### Capability

**Unit of specialized cognitive know-how**, modular and composable. Organized in a hierarchical tree. **Reserved in the strict sense to Layer 2 · Cognition.**

**NOT a plugin. NOT a prompt. NOT a system prompt. NOT a tool. It is knowledge.** The Capability **decides which tool to invoke**. Analogous terms in other layers: **Connector** (knowing how to access source systems · Layer 4), **Template** (tailoring of a canonical instrument · Layer 1), **feature** (internal operation of a larger Capability). **Capability portability (MUST)**: it runs on any conformant AgencyDomain; it is real property of the client.

**Four rules of the tree**: any node is a valid Capability · it is scalable (new branches without breaking existing ones) · it is heritable (inherits context and vocabulary from ancestors) · composable.

**Canonical anatomy — nine components**: (1) **identity** (name + position in the tree) · (2) **vocabulary** · (3) **procedural knowledge** · (4) **declarative knowledge** · (5) **heuristics** · (6) **associated tools** (Layer 4) · (7) **parent Capabilities** (inheritance) · (8) **maturity state** (`Draft` / `Current` / `Deprecated`) · (9) **version**. Components 2–5 (vocabulary · procedural · declarative · heuristics) are the body of know-how that distinguishes a Capability from an elaborate prompt.

**Conformance (MUST/SHOULD/MAY)**: hierarchical tree structure (MUST) · any node is a valid Capability (MUST) · composability (MUST) · anatomy with vocabulary + procedural + declarative + heuristics (MUST) · explicit versioning (MUST) · **declared maturity state `Draft`/`Current`/`Deprecated` (MUST)** · selection by the cognition, not direct execution (MUST) · declaration of locality and offline availability (MUST) · portability across conformant AgencyDomains (MUST) · **verticals as a dedicated root (SHOULD)** · open marketplace (MAY).

#### Locality and availability — operational classification of Connectors

The classification is predicated on the **Connector** (access is what resides and needs a network; knowledge has no locality). Every conformant Connector MUST declare its position on two orthogonal axes:

**Locality axis**:
- **Cloud-resident** — lives in a remote service (DTE-SII, Transbank, weather API).
- **Edge-resident** — lives at the physical site, associated with hardware (ESC/POS-Printer, Cash-Drawer, Local-Pinpad).
- **Hybrid** — local component + cloud component (Client-DTE, Client-Pinpad-Deferred-Processing).

**Offline availability axis**:
- **Online-only** — requires network to execute.
- **Offline-capable** — executes without network; queues if it emits outward.

**Canonical matrix**:

|   | Online-only | Offline-capable |
|---|---|---|
| **Cloud-resident** | DTE-SII (no local client) · Transbank Onepay | (typically migrates to hybrid) |
| **Edge-resident** | (unusual combination) | ESC/POS-Printer · Cash-Drawer · Sensor |
| **Hybrid** | (unusual combination) | Client-DTE · Client-Pinpad |

Operational rule with distributed Layer 3: **a senior edge Botlet, without network, operates by invoking exclusively edge-resident Connectors and the local part of hybrid ones**.

**Required properties (locality/availability)**:
- Explicit declaration of the Connector's locality — cloud-resident / edge-resident / hybrid (MUST).
- Explicit declaration of offline availability — online-only / offline-capable (MUST).
- Specification of offline behavior for offline-capable — what it does without network, what it queues, how it drains (MUST).
- Deterministic resolution of which component runs in hybrids — under what conditions the local runs; under which it invokes the cloud (MUST).

#### Regulatory certification resides in the certified component, not the Botlet

For regulated operations (DTE-SII, PCI-DSS, sanitary registry, etc.), **regulatory certification resides in the certified component the Botlet invokes — the certified Connector, accompanied by the regulated Capability that carries the normative knowledge —, not in the Botlet**. The separation is justified because the Botlet is **generated, regenerable code**; certifying it a priori is impossible and certifying it between regenerations contradicts its nature.

**Canonical pattern**: the **Botlet orchestrates** (knows the flow, validates pre-conditions, captures the event, formats the request) and the **certified Connector executes the regulated operation** (receives the request, executes under norm, returns the receipt); the **regulated Capability** supplies the normative knowledge with which cognition governs the pair. Uniform by industry: `Charge-Table`→`DTE`, `Process-Payment`→`PCI-DSS-Gateway`, `Dispense-Prescription`→`Sanitary-Registry`, etc.

**Required properties (regulated)**:
- Regulated components declare their regulatory regime — which norm, before which regulator, with what certification number (MUST).
- Certified Connectors immutable between audits; they change only under a regulatory process (MUST).
- Botlets may invoke certified components without restriction — the contract is stable; they are invoked like any other (MUST).
- Auditability of the boundary — the log distinguishes Botlet operations (business logic) from certified-component operations (regulated operation) (MUST).

### Assistant vs Autonomous Agent

A critical distinction that cuts across Layer 2 and Layer 3. **It is not hierarchical**.

| Axis | **Assistant** | **Autonomous Agent** |
|---|---|---|
| Layer | Layer 2 (Cognition) | Layer 3 (Autonomy) |
| Mode | Reactive | Proactive |
| Activation | Waits for the human's input | Pursues objectives without continuous input |
| State | No persistent state | Persistent state |
| Botlets | No own Botlets | Maintains and regenerates Botlets |
| Life | Per session | Persistent in the background |

**They are governed differently**: the Assistant operates under the human's immediate control (conversational validation, light governance); the Autonomous Agent operates without immediate supervision (systemic validation). **The Autonomous Agent exercises the five pillars of Trust Infrastructure (MUST)** — robust governance, not just access controls.

The **Agent** umbrella covers a third member beyond these two modes: the **Agentlet** (packaged agent of bounded charter; a catalog piece, not an inhabitant — see its section above). The modes describe how the full agent operates; the Agentlet is a piece the full agent engenders and maintains.

### Facet · sixth canonical primitive

Atomic reusable component of **Layer 1 (Interaction)**: drawing board, catalog-picker, color matrix, calendar, clickable map, slider, drag-and-drop, dynamic form, creative canvas. One of the many faces interaction can take.

**Facet vs Botlet — ontological distinction**:

| Axis | **Facet** | **Botlet** |
|---|---|---|
| Layer | Layer 1 (Interaction) | Layer 3 (Autonomy) |
| Nature | Instrument of interaction | The agent's muscle memory |
| When it operates | During active conversation | In the background, without cognition present |
| Activation | The cognition invokes it explicitly | Pattern Recognition or external call |
| Fallback guarantee | NO — the agent returns to conversation | YES — the cognition executes manually |
| Cycle | No regeneration | `95/4/1` cycle with regeneration |
| Persistence | Ephemeral (lives as long as the task lasts) | Persistent between sessions |
| Maturity | Not applicable | Junior · learning · senior |
| Reuse | Flat catalog of instruments | Catalog by capability and domain |

> *The Botlet is muscle memory. The Facet is an instrument the agent picks up while it thinks.*

**Two canonical uses**:
1. **Direct invocation by the cognition** — during conversation, the agent composes an ephemeral surface with Facets; the user interacts; information returns. It realizes the *GUI on-the-fly* regime.
2. **Composition in presentation Botlets** — shells and views (Layer 1 Botlets) assemble Facets plus orchestration logic.

**Declared bounded interaction (embedded Facet)**: a piece of already-materialized information can carry interaction over its own data without ceasing to be reproducible. The canon distinguishes two interactivities:

| What distinguishes them? | **Free exploration** | **Declared bounded interaction** |
|---|---|---|
| Query to the source | yes, arbitrary (ad-hoc drill/pivot) | no — operates on the already-materialized snapshot |
| Space | open | declared (bounded dimensions and values) |
| Reproducibility | lost | maintained |
| Generation | exceeds `G1` | `G1` (configuration, not code) |
| Where it lives | another Botlet / cognition | in the piece itself, via Facet |

**Free exploration** stays **OUTSIDE** the information proto-Botlet (a conformant Botlet **MUST NOT** absorb it). **Declared bounded interaction** is realized via an **embedded Facet** bounded to a declared dimension of the piece's own data: on activation, the *data-bound* elements (KPIs as declared aggregations — `sum`, `ratio` —, distributions, traffic lights) are **recomputed client-side** over the filtered subset, **without new Capability invocations**. It refines (does not contradict) the Facet vs Botlet distinction: the Facet stays ephemeral and without fallback, but its role as an embedded Facet within a piece is recognized.

**Agentive behavior**: the agent **estimates in real time** whether the information is best obtained verbally or visually. Heuristics:
- Low dimensionality + well structured → conversation.
- High dimensionality or hard to verbalize (color, position, shape) → Facet.
- The user already has it in visual form → Facet.
- Comparison among multiple options → Facet.
- Open creative work → canvas Facet.

**Anti-heuristics**: closed and verbal question · channel without graphical capability (voice, IVR, SMS) · the cost of loading a Facet exceeds the benefit · it interrupts the conversational flow.

**Anatomy of the Facet** — six canonical components:
1. Identity (canonical name + version).
2. Interaction modality (input/output).
3. Input schema.
4. Output schema.
5. Internal state (selections, edits, undo stack).
6. Channel compatibility (web, mobile, kiosk, unsupported on voice).

**Flat catalog**: Facets are not hierarchized; each is atomic. Emergent catalog: `drawing-board`, `catalog-picker`, `color-matrix`, `range-calendar`, `clickable-map`, `multi-slider`, `dragdrop-order`, `dynamic-form`, `creative-canvas`, `file-picker`. The spec does not close the catalog.

**Required properties**:
- Declared identity and version (MUST).
- Explicit input and output schemas (MUST).
- Declared channel compatibility (MUST).
- Atomicity — it does not internally compose other Facets (MUST).
- Explicit Facet vs Botlet distinction in documentation (MUST).
- Direct invocability by the cognition during conversation (MUST).
- Composability within shell and view Botlets (MUST).
- Preservation of the piece's reproducibility when composed as an embedded Facet — client-side recompute, no Capability invocations (MUST).
- Declared bounded interaction composed in a materialized piece — declared control space, no new queries (MAY).
- Public catalog of Facets available to the AgencyDomain (SHOULD).
- Documented invocation heuristics for the cognition (SHOULD).

### The agent's three evolutionary phases

1. **Specialized** — one agent per domain. The market's current phase (early 2026).
2. **Orchestrators** — one agent coordinates multiple specialists.
3. **Multi-specialists** — deep multi-domain expertise in a single agent. A future phase.

**The architecture is the same in all three phases.**

---

## 8 · The market — AI value chain

A two-dimensional model: **eleven sequential links × four depths**.

### Eleven links (coverage)

1. **Data** · 2. **Model** · 3. **Access** · 4. **Agents** · 5. **Specializations** · 6. **Runtime** · 7. **Firewall** · 8. **Observability** · 9. **Tools** · 10. **Integrations** · 11. **Environment**

### Four depths

- **Wrapper** — consumes via third-party APIs/SDKs.
- **Platform** — operates its own capability over Core components.
- **Core** — builds the foundational capability with its own technology.
- **Infrastructure** — provides the substrate.

### Canonical matrix

| Link | 4 · Infrastructure | 3 · Core | 2 · Platform | 1 · Wrapper |
|---|---|---|---|---|
| **1 · Data** | AWS/GCP/Azure | Scale AI/Labelbox · Hugging Face | — | — |
| **2 · Model** | NVIDIA · AWS/GCP/Azure | OpenAI · Anthropic · Google · Meta · DeepSeek/Qwen/Ernie | Hugging Face | — |
| **3 · Access** | — | Anthropic · DeepSeek/Qwen/Ernie | OpenAI · Google · Perplexity · ultraPRO | — |
| **4 · Agents** | — | Perplexity · DeepSeek/Qwen/Ernie · Agentia (priv.) · Soveria (pub.) · (LangChain/Graph) · (AutoGPT/CrewAI) | OpenAI · Anthropic · Google · GitHub Copilot | — |
| **5 · Specializations** | — | Perplexity · GitHub Copilot · Cursor/Replit · Devin · Harvey/Jasper/Fin · umeeta | OpenAI | — |
| **6 · Runtime** | — | OpenAI · Devin · Agentia · Soveria · ultraPRO · (LangChain/Graph) · (AutoGPT/CrewAI) | — | — |
| **7 · Firewall** | — | Guardrails/NeMo/Lakera · ultraPRO | — | — |
| **8 · Observability** | — | Langfuse/LangSmith/W&B · ultraPRO | — | — |
| **9 · Tools** | — | OpenAI · Anthropic · Google · Devin · ultraPRO · (LangChain/Graph) · (Pinecone/Weaviate) | — | — |
| **10 · Integrations** | — | Zapier/Make/n8n · ultraPRO | — | — |

Derived from the actor table of Chapter 6 (representative product families of the current market). Parentheses — e.g. (LangChain/Graph) — indicate a framework or meta-tool (to build with, not to use).

> ultraPRO occupies the architectural category **complete enterprise gateway** — simultaneous Core in links 6-10 plus a Platform extension in Access, under the tripartite Cloud + Client + Local pattern.

> **Link 11 · Environment**: it stays outside the matrix — it is the territory on which links 1-10 act (the enterprise systems the agent turns into invisible backend), not a link an AI actor occupies at some depth.

### Four strategic archetypes

- **Comprehensive platform** — broad coverage (3+ links); Core in its native link, Platform in the adjacent ones.
- **Vertical specialist** — focal coverage, Core depth.
- **Domain infrastructure** — zonal coverage, Core depth in several links.
- **Substrate provider** — minimal coverage, Infrastructure depth.

### Observability (link 8) · six canonical capabilities

A complete implementation of Observability for agentive systems covers six distinct capabilities:

1. **Tracing** — end-to-end traceability of each operation (structured events correlated by trace ID).
2. **Cost monitoring** — token/resource consumption in real time per model/user/project/tool; in mature systems it is prediction, not just recording.
3. **Quality evaluation** — systematic verification of responses; two sub-modes: automated (eval as a service) and human (sample review).
4. **Performance metrics** — latency (p50/p95/p99), throughput, availability, success rate (distinguished by Botlet/agent/system).
5. **Debugging and reproducibility** — replay of invocations; complexity added by the probabilistic LLM, persistent state, and Botlet regeneration.
6. **Alerts and anomalies** — proactive out-of-pattern detection; may trigger circuit breakers, rollback, or escalation.

> A market fragmented by design: a mature organization combines two or three products (an "observability stack"), not a monolithic solution.

### Carbon World · MEO

- **Carbon World** — link 11 extended to the physical world (IoT, industrial processes). Patterns: edge computing, digital twin.
- **Four sub-categories of the Environment** (decreasing maturity, increasing regulation):
  1. **Traditional enterprise systems** — legacy ERPs/CRMs/DBMS; digital but institutional; the most mature (integration: Zapier · Make · Workato · MuleSoft, still mostly agentic, not autonomous).
  2. **Industrial physical world** — manufacturing and energy (SCADA · MES · PLCs · sensors); higher capturable value and more conservative (plant-safety regulation).
  3. **Mobile physical world** — transport, logistics, agriculture (fleets, drones, agricultural equipment); adds intermittent connectivity and geographic coordination; faster adoption.
  4. **Biological world** — genomics, medical monitoring, EHR, pharmacovigilance; greatest human impact and maximum Trust demand (HIPAA · health GDPR).
- **MEO — Model Engine Optimization** — practices for getting frontier models to reference the actor. The equivalent of SEO in agentive discovery.

---

## 9 · Canonical application — Real-time knowledge

```
┌──────────────────────────────────────────────────────────────────┐
│      VARNISHED KIMBALL = CLASSIC KIMBALL + AGENTIVE LAYER         │
│                                                                  │
│    SOURCE → ETL → PRESENTATION → BI APPS → AGENT → HUMAN          │
│                                                                  │
│    ─────────────────────────────────────────────────────────     │
│    METADATA + SEMANTIC LAYER + TRUST SCORE + AI CERTIFICATION    │
│         (cross-cutting — strategic asset)                        │
└──────────────────────────────────────────────────────────────────┘
```

**Essential components** that distinguish Varnished Kimball from classic Kimball:

- **Explicit semantic layer**.
- **Trust Score per datum**.
- **AI Certification**.
- **Observability of agentive queries**.

**Mapping to the hyperscalers** — each implements base Kimball with its own terminology; the functional equivalence is direct:

| Provider | Warehouse / ETL | BI App | Governance | Unifying layer |
|---|---|---|---|---|
| **Azure** | Synapse Analytics | Power BI | Purview | Fabric |
| **AWS** | Redshift | QuickSight | DataZone | Lake Formation |
| **Google Cloud** | BigQuery | Looker | Dataplex | — |
| **Databricks** | Lakehouse + Medallion | — | Unity Catalog | — |

Medallion → Kimball: **Bronze** = Source (raw) · **Silver** = ETL (clean/conformed) · **Gold** = Presentation. No hyperscaler yet has a complete implementation of the **agentive layer** of Varnished Kimball.

---

## 10 · Operation

### CRUDLEX

Canonical model of granular permissions: **C**reate, **R**ead, **U**pdate, **D**elete, **L**ist, **E**xecute. Applicable per user, agent, and context.

**Preconfigured levels** (level → enabled CRUDLEX):

| Level | CRUDLEX enabled |
|---|---|
| **FULL** | `C R U D L E` |
| **READ-WRITE** | `C R U D L` (no E) |
| **READONLY** | `R L` |
| **SAFE** | `R L E` (E limited to reversible operations) |
| **NO-SEND** | `C R U L` (no E) |
| **NO-DELETE** | `C R U L E` (no D) |

### Policy catalog — five categories

A well-designed agentive system has active policies in **all five**:

1. **Tool policies** — which tools the agent may invoke, over which resources (granularity by agent, tool, and scope).
2. **Data policies** — which classes of data it may query or emit, by sensitivity.
3. **Schedule and threshold policies** — when and with what magnitude/risk thresholds it acts.
4. **Identity policies** — which identities operate on behalf of the agent and how they authenticate (federated identity).
5. **Validation policies** — which validations apply before executing (they connect with Pillar 3).

**Hierarchical composition with downward monotonicity** (MUST): the agent's policy inherits the restrictions of the higher ones and may only **add** restrictions, never remove them. It prevents accidental privilege escalations.

### Append-only log

An immutable, cryptographically chained record of every action. A central component of Audit.

**Minimum content of each trace**: the agent's identity, invoked capability, executed tool, **hash of parameters and result** (not the raw content — sensitive data lives in a separate store with its own retention policy), timestamp, context, and `previous_log_hash` that chains with the prior record. Non-negotiable property: the log keeps **hashes, not content**.

### Human approval

Halts an operation and requests authorization before executing. Triggered by: **explicit policy**, **threshold**, **agent uncertainty**.

### Canonical validation (Pillar 3)

- Hallucination detection · validation of structured responses · prompt injection prevention · DLP · tokenization.

### Operational business continuity vs agentic fallback guarantee

Two complementary mechanisms:

| Mechanism | When it operates | What it resolves | Provided by |
|---|---|---|---|
| **Agentic fallback guarantee** | Junior, learning, or senior Botlet with a new variant (cognition available) | Environment changes the Botlet did not anticipate | Agentive spec (Layer 2 + Layer 3) |
| **Operational business continuity** | Senior Botlet down by exogenous cause, no cognition available | Continuity when no computational component operates | Client's protocol |

The agentic fallback guarantee **produces the Botlet's maturity** (without it, it does not mature); operational continuity operates over senior Botlets down by exogenous cause and does not bear on maturity. Recognizing them as separate prevents the client from attributing to the architecture a failure that belongs to their protocol.

### AgencyDomain degradation modes

Four canonical modes according to the failure scenario. The organization must be able to identify at every moment which mode each site operates in.

| Mode | Condition | Who sustains operation |
|---|---|---|
| **Normal** | All components active | Full parallel topology |
| **Cognition down** | Layer 2 unreachable, edge OK | **Autonomy Path** sustains; cognition will rescue on return |
| **Edge offline** | Edge Botler without connection to central; isolated site | **Senior Botlets** against local DB + edge-resident Connectors |
| **Total operational continuity** | Cognition + edge down by exogenous cause | **Site's manual protocol** |

**Automatic transition up to `Edge offline`** — the architecture degrades on its own. **Transition to `Total operational continuity` is governed by the site's protocol** — a human activates it explicitly. Key difference: the first three modes are the architecture's responsibility; the fourth is the client's responsibility.

### Transition traceability — canonical log tags

- `mode-change: continuity-operational` — when the site activates the manual protocol.
- `provenance: manual-continuity` + `original-timestamp` — physical records entered retroactively.
- `provenance: edge-queue-replay` — drainage of the edge queue after the network returns.
- `agentic-fallback` vs `operational-continuity` — auditable distinction between cognition rescuing and human sustaining.

### Required properties (Resilience Pillar + Continuity)

| Property | Level |
|---|---|
| Explicit distinction in product documentation | MUST |
| Operational continuity protocol documented per site | MUST |
| Drills at minimum quarterly frequency | SHOULD |
| Four degradation modes recognizable by the organization | MUST |
| Traceability of the transition to continuity mode in the append-only log | MUST |
| Auditable distinction between agentic fallback and operational continuity | MUST |
| Retroactive reconciliation of physical records into the system | MUST |

---

## 11 · Evolution frontier

Three live **technical** horizons:

1. **Non-LLM cognition** — Layer 2 admits symbolic, hybrid, multimodal cognition.
2. **Federation (`A2A` between AgencyDomains)** — open protocols in evolution. Intra-AgencyDomain coordination (via the `A2A` protocol) is already mature; `A2A` *between* distinct AgencyDomains is open work.
3. **Carbon World** — extension of Layer 4 to the physical world.

The human book counts **four live frontiers**: these three technical horizons plus a **fourth institutional frontier** — agentive sovereignty and citizenship (**AgentNation**, below).

### Botlet generations — G1/G2/G3

An evolutionary model of how the Botlet's code is born as the state of the art of cognition advances. **The architecture is the same in all three**; what changes is the **scope of Engineering**. An implementation can operate in `G1` today and migrate toward `G3` without re-architecture.

- **G1** — the agent configures pre-forged proto-Botlets from the catalog (it does not write the body). If none fits, it specifies a new one to forge in the next Preparation.
- **G2** — the agent co-writes proto-Botlets with human or model assistance.
- **G3** — the agent generates the Botlet's complete code at Engineering time (the asymptotic scenario).

**G1 admits rich expressive configuration**: what defines `G1` is that the agent does not write the proto-Botlet's body; the configuration may be as rich as a compositional `DSL` with evaluable formal expressions. The `G1`/`G3` distinction is about **authorship of the body**, not expressiveness of the config.

**`G1`/`G2` edge** (test: *"does the code belong to the invoked Capability or to the proto-Botlet itself?"*): a formal evaluable expression that is a **parameter of a well-defined Capability** (`SQL`→`execute-sql`, a chart specification→`render-chart`, filter→`filter-stream`) is configuration → **`G1`**. An expression that **extends/overrides the proto-Botlet's internal logic** (callbacks, lambdas it evaluates internally) is the agent's code → **`G2`**.

**Reconciliation — two distinct axes, not the same arrow**:

| Axis | What does it measure? | Direction of "advance" |
|---|---|---|
| **Authoring capacity** | How much it can forge: configure (`G1`) → co-write (`G2`) → generate (`G3`) | Toward `G3`, with the state of the art of cognition |
| **Operational maturity** | For a recurring operation, how much pre-forged is reused vs regenerated (`95/4/1` cycle) | Toward reuse (`G1`), as the Botlet matures junior → senior |

`G3` capacity **is better spent producing `G1` reuse**: the destiny of `G3` is a richer `G1` catalog, not the live regeneration of everything. For a **platform** proto-Botlet, `G1` is **terminal by design**, not a way station. The most advanced agent **generates less because it has crystallized more**, and reserves generation for the edge (the 4%+1% of the cycle). Brain parallel: cortex = Cognition (Layer 2); cerebellum + basal ganglia = Autonomy (Layer 3). Sophistication is **stratifying so that the cognition does not have to do everything**.

### AgentNation

A public-regime AgencyDomain that adopts the model of agentive citizenship. The agents are **citizens**, not products. Ontological distinction: a marketplace lists products; AgentNation recognizes citizens. Open architectural work.

---

## 12 · Canonical glossary (alphabetical)

### A

- **A2A — Agent-to-Agent** — a name reserved for the **relation between distinct AgencyDomains** (distinct agents; federation). Communication within a single AgencyDomain **is not "internal A2A"**: it is **intra-AgencyDomain coordination**, and when it uses that transport one says **via the `A2A` protocol**. The Layer 2 → Layer 3 interface goes over `MCP`, not `A2A`.
- **Account** — a commercial concept; it may own multiple AgencyDomains.
- **AgencyDomain** — computational scope with its own identity where autonomous agents and Botlets dwell, **where the Capabilities are hosted and run**, and where the resources that sustain them live. Minimal unit of deployment.
- **AgencyDomain degradation modes** — Normal · Cognition down · Edge offline · Total operational continuity. The first three transitions are automatic; the fourth requires human activation by protocol.
- **AgencyDomain portability** — structural property: a conformant AgencyDomain migratable to another conformant platform without rewriting. Three conditions: Botlets against canonical primitives, exportable DB, portable Trust Layer.
- **Agent** — umbrella term covering three members: the **Assistant** (Layer 2, reactive), the **Autonomous Agent** (Layer 3, proactive, an inhabitant) and the **Agentlet** (Layer 3, packaged, a catalog piece). The distinction is not hierarchical.
- **Agentlet** — **eighth canonical primitive**. Packaged unit of Layer 3, sibling of the Botlet, whose body invokes **bounded inference** within a charter declared in the spec. The home of the task recurrent in form but interpretive in every instance. **The Agent has an agenda; the Agentlet has a charter.** An instance of a proto-Agentlet; hosted by the Botler (`cognition_call`); fallback to full Cognition. The intermediate economic rung between Botlet and Cognition.
- **Agent First** — governing principle: the agent's experience takes precedence over the human's.
- **Agentic** — the world of complementary agents. Incremental evolution.
- **Agentic fallback guarantee** — the cognition executes when the Botlet fails. **The process never stops.** **What produces the Botlet's maturity.**
- **Agentive (Agentive World)** — agents as the sole interface. Fundamental transformation.
- **Agentive Architecture** — technical design that materializes the Agentive World. Four layers (Interaction, Cognition, Autonomy, Access), governed by cross-cutting Trust Infrastructure and ordered by the Agent First principle.
- **AgentNation** — public AgencyDomain with a model of agentive citizenship.
- **AI value chain** — two-dimensional model of 11 links × 4 depths.
- **Append-only log** — immutable, cryptographically chained record.
- **Assistant** — reactive agent, no Botlets, no persistent life. Layer 2.
- **Attention** — one of the **agent's three times**. The time in which the agent interacts with users or events in real time. Layer 1 active, critical path, priority.
- **Audit** — Pillar 2 of Trust Infrastructure. Reconstructing after the fact **what the agent did, when, why, and over what data**. Central mechanism: the append-only log; completed by trace, lineage, and identity tagging.
- **Autonomous Agent** — proactive, persistent life, maintains Botlets. Layer 3.
- **Autonomy Path** — one of the two paths of the parallel topology. Fast, cheap, repetitive. For Botlets over stable patterns.

### B

- **BCA — Bounded Concerns Architecture** — architecture of the pre-agentive state.
- **Botlet** — self-evolving automation unit. Non-LLM code. Muscle memory. `95/4/1` cycle.
- **Botlet, emergent** — generated by Pattern Recognition when it detects an unanticipated repetitive pattern.
- **Botlet, facade** — Layer 3 Botlet that exposes an operational surface with a stable contract in Layer 1, propagated human identity.
- **Botlet, junior** — initial phase. `60/35/5` proportion. Depends on cognition.
- **Botlet, learning** — intermediate maturity phase. `85/12/3` proportion.
- **Botlet, operation** — **Layer 3** Botlet that executes business logic invoked from Layer 1 (views and shells). Most reusable in the catalog. Examples: charge a table, print a kitchen ticket, close a shift.
- **Botlet, seed** — generated by cognition at the design team's request, as part of the initial product.
- **Botlet, senior** — mature phase. `99+/<1/~0` proportion. Only exogenous failures. Offline-operable.
- **Botlet, surface (shell)** — **Layer 1** Botlet acting as a container: layout, navigation, session, shared state. Specific to each product.
- **Botlet, view** — **Layer 1** Botlet that materializes a screen or panel within a shell. Assembles Facets + orchestration logic. Reusable across shells.
- **Botlet generations — G1/G2/G3** — evolutionary model of the birth of the Botlet's code. **G1**: configures pre-forged proto-Botlets (does not write the body). **G2**: co-writes the proto-Botlet. **G3**: generates the complete code (asymptotic). It changes the scope of Engineering, not the architecture. G3 capacity is better spent producing G1 reuse; for a platform proto-Botlet, G1 is terminal by design.
- **Botler** — **generic** Layer 3 runtime (does not understand domain) that executes the **Lets** of the layer: Botlets and Agentlets. A type (a normed construct of the Botlet spec), not a proper name. No subtypes by domain; validates by orchestrating (controlled handle with `capability_call` · `log` · `cognition_call`); exposes an `MCP` server to the Cognition. **1 Process = 1 Botler + N Lets**.
- **Botler, central** — orchestration, planning, reporting Botler in distributed Layer 3.
- **Botler, edge** — local-transaction Botler in distributed Layer 3. One per physical site.
- **BYOModel** — Bring Your Own Model. Substitution of the default provider. SHOULD for regulated markets.

### C

- **Capability** — **cognitive** know-how, modular and composable, reserved to **Layer 2 · Cognition**. NOT a plugin, NOT a prompt, NOT a tool. **It is knowledge.** Exposes **features**; is **portable** (runs on any conformant AgencyDomain).
- **Connector, cloud-resident** — lives in a remote service. Typically online-only.
- **Connector, edge-resident** — lives at the physical site, associated with hardware. Typically offline-capable.
- **Connector, hybrid** — local component + cloud component. Offline-capable with queuing.
- **Connector, offline-capable** — executes without network. Queues if it emits outward.
- **Connector, online-only** — requires network.
- **Capability, regulated** — carries the normative knowledge of an operation subject to certification (DTE-SII, PCI-DSS, etc.). Regulatory certification resides in the **certified Connector** that executes the operation, not in the Capability nor in the Botlet.
- **Capability portability** — a conformant Capability runs on any conformant AgencyDomain; it makes it real property of the client. Distinct from AgencyDomain portability.
- **Carbon World** — link 11 extended to the physical world.
- **Cluster** — instances of the same AgencyDomain sharing load.
- **Codex, proprietary** — private catalog of proto-Botlets, Capabilities, and patterns that an implementer curates over the public reference implementation, refined by its real cases. One of the four membership modes of a catalog community. The runtime is common; the codex is one's own (it encapsulates the competitive advantage). Canonical instance: **ucodex** (Grupo Ultra).
- **Cognition Path** — one of the two paths of the parallel topology. Slow, costly, decisive. For conversation, new decisions, unanticipated cases.
- **Common catalog** — proto-Botlets accumulate in shared catalogs with network effects. Modes: private contract · proprietary codex · open public catalog · sovereign agreement.
- **Conformed dimensions** — a Kimball concept: dimensions shared across data marts that guarantee inter-mart consistency.
- **Connector** — knowing how **to access source systems** (a connection with execution power; NOT cognitive knowledge). **Layer 4 · Access.** The legacy API brought into the Agentive World becomes a Connector, not a Capability.
- **CRUDLEX** — Create, Read, Update, Delete, List, Execute.

### D

- **Declarative quality contract** — a Botlet's quality attributes declared as structured properties: Freshness · SLA · Degradation policy · Audience · Refresh policy. Trust Infrastructure audits them uniformly.
- **Declared bounded interaction** — interaction that operates over the **already-materialized snapshot** of a piece, in a **declared** space, that **maintains reproducibility** and is **`G1`** (configuration, not code). Lives in the piece itself via an **embedded Facet** (client-side recompute, no Capability invocations). Distinct from **free exploration** (arbitrary query to the source, exceeds `G1`).
- **Depth** — vertical dimension: Wrapper / Platform / Core / Infrastructure.
- **Derivation chain** — structural relation `use cases → required Botlets → proto-Botlets from the catalog`. Every conformant Botlet MUST be traceable along it; the log records the origin proto-Botlet.
- **Digital twin** — a pattern for the Carbon World.
- **DLP — Data Loss Prevention** — detection of unauthorized PII.
- **Domain** — commercial synonym for AgencyDomain.
- **Dominion** — a Domain obtained by an agent in a public AgencyDomain under the AgentNation model.

### E

- **Edge computing** — distribution of Layer 3 near the physical process.
- **Engineering** — one of the **agent's three times**. Bridge between Preparation and Attention: converts latent capacity into executable capacity for a concrete case. Configures seed Botlets, validates deploy. Medium term (minutes to hours).
- **Enterprise AI gateway** — Core in Runtime+Firewall+Observability+Tools+Integrations.

### F

- **Facet** — **sixth canonical primitive**. Atomic reusable component of Layer 1: drawing board, catalog-picker, calendar, map, slider, drag-and-drop. An instrument the cognition invokes during conversation or that presentation Botlets assemble. **It is NOT a Botlet** (Layer 1 vs Layer 3 · ephemeral vs persistent · without agentic fallback vs with).
- **feature** — an internal operation a Capability exposes (the equivalent of *feature/operation/skill/method*). Capability vs feature test: operational independence + cognitive identity + reusability; if one fails → it is a feature of the containing Capability.
- **Federation** — communication between distinct AgencyDomains.
- **Firewall** — link 7. Security, governance, prompt injection prevention.

### G

- **Governance** — Pillar 1 of Trust Infrastructure.
- **GUI on-the-fly** — Regime 2 of Layer 1. A graphical surface adapted to the task, lives as long as the task lasts.
- **GUI, persistent (as facade Botlet)** — Regime 3 of Layer 1. The stable surface of a facade Botlet (Layer 3, typically seed) for repetitive operational roles.

### H

- **Hallucination** — a factually incorrect statement. Detection in the Validation Pillar.
- **Human approval** — authorization before executing a critical operation.
- **Hybrid (regime)** — AgencyDomain with a private core + partial public exposure.

### I

- **Information Instrument** — the canonical **type** of the information family (the class: report / dashboard). Distinct from the **Information Product**, which is its manifested instance.
- **Information Product (`PI`)** — manifested/delivered instance of the information family (the concrete manifestation of an Information Instrument). Each `PI` is its own Botlet/service specialized from a shared engine (platform proto-Botlet). **It is NOT a canon primitive** — it lives in the practice of information.
- **intra-AgencyDomain coordination** — communication between runtimes (Botlers) of the **same** AgencyDomain. **It is NOT "internal A2A"**: they are runtimes of the same agent, not distinct agents. When it uses that transport one says **via the `A2A` protocol**. Counter-concept of `A2A` (relation between distinct AgencyDomains).

### J

- **JSR — Java Specification Request** — canonical format of Java specifications (Sun Microsystems / Oracle). **JavaSpaces (JSR-000148, 1999)** is the conceptual analog of AgencyDomains.

### K

- **Kimball / Varnished Kimball** — dimensional modeling + agentive layer.

### L

- **Layer 1 — Interaction** — human-AI interface with three GUI regimes.
- **Layer 2 — Cognition** — the agent's brain.
- **Layer 3 — Autonomy** — persistent life. Admits geographic distribution (distributed Layer 3).
- **Layer 3, distributed** — canonical pattern for multiple physical presence. Central Botler + N edge Botlers.
- **Layer 4 — Access** — execution power with Trust Infrastructure.
- **Link** — functional layer of the value chain (1 to 11).
- **LLM** — Large Language Model.

### M

- **manifestation** — actualization of the Botlet's latent disposition in the world, perceptible or not (potency → act). NOT "appearance". Abstract genus: information → leaves a `PI`; action → effect on the world; decision → per its practice.
- **MCP — Model Context Protocol** — open canonical protocol for Layer 4 tools and for the internal Layer 2 → Layer 3 interface (Cognition client, Botler server). Anthropic, November 2024.
- **MEO — Model Engine Optimization** — the equivalent of SEO in agentive discovery.
- **Meta-Cognitive Platform** — a platform category that administers the **economics of cognition** (G1 pre-forged muscle vs fresh-cognition fallback, `95/4/1` cycle, junior→senior maturation, crystallization). **Vergis** is the reference implementation. **NOT abbreviated to "MCP"** (the acronym taken by Model Context Protocol).
- **Mira** — proper name of a **platform** proto-Botlet for informational operation from the reference implementation's catalog.
- **Muscle memory** — the canonical metaphor of the Botlet.
- **Let (plural: Lets)** — the **proper name of the genus** of the packaged pieces the Botler hosts and executes; normed vocabulary (like Botler), not a primitive. Descriptively: the packaged unit of Layer 3. Two species: **Botlet** (non-LLM code) and **Agentlet** (bounded inference). The shared apparatus is predicated of the genus; the differential guarantees, of each species. Invariant across ES/EN. Canonical relation: **1 Process = 1 Botler + N Lets**.
- **Nadella Line** — see N.

### N

- **Nadella Line** — threshold between the Agentic World and the Agentive World. *Does the human open applications to do their work?* (canonical formulation; *The Real-Time Enterprise* conjugates it in the second person and *AURA* in the executive's voice — the three are official equivalents).

### O

- **Observability** — link 8 of the value chain: the layer that **observes, measures, and feeds back** on the AI system in production. Its question: *how does it work?* Without it, agents are black boxes.
- **Online enterprise** — data current to the day, depends on humans to interpret.
- **Operational business continuity** — manual protocols for a senior Botlet down by exogenous cause with cognition unavailable. Distinct from and complementary to agentic fallback.

### P

- **Parallel topology** — canonical model of the four layers. Layers 2 and 3 are **parallel paths** between Layer 1 and Layer 4, not stages in series.
- **Pattern Recognition** — detection of repetitive patterns. Activates emergent Botlet generation.
- **Preparation** — one of the **agent's three times**. *Mise en place* — the agent refines the catalog, improves capabilities, outside the service window. Batch / off-peak regime.
- **Private (regime)** — AgencyDomain in a controlled perimeter. No public access.
- **Prompt injection** — manipulation via malicious inputs.
- **proto-Agentlet** — a pre-forged piece of interpretive capability that the agent **configures** in its Engineering time to instantiate an Agentlet. It contains the body (the charter's structure, the skeleton of the operating prompt, input/output contracts, escalation thresholds); the Agentlet is the configured instance. Same classes (tempered · platform), same derivation chain and same catalogs as the proto-Botlet.
- **proto-Botlet** — **seventh canonical primitive**. A pre-forged piece of operational capability that the agent **configures** in its Engineering time to instantiate a Botlet. The proto-Botlet contains the code; the Botlet is the configured instance. Two classes: **tempered** (specific code; bounded parameterization) · **platform** (generic engine; compositional configuration; covers N functions). Public catalogs (AgencyDomains.org) or private (proprietary codices).
- **Public (regime)** — publicly accessible AgencyDomain.

### Q

- **Quantum Leap** — threshold enabled by the collapse of the cost of the analytical question: when asking the data stops being expensive, slow, or mediated by a human, the organization crosses from **online enterprise** to **real-time enterprise**. A change of operating regime, not an incremental BI improvement.

### R

- **RAG — Retrieval-Augmented Generation**.
- **Real-time enterprise** — detects, interprets, decides, and acts autonomously.
- **Regime** — deployment mode of an AgencyDomain by access boundary. **Technically equivalent structure; the regime changes, not the capability.**
- **Resilience** — Pillar 4 of Trust Infrastructure.
- **Runtime** — link 6. The agent's operating environment. Corresponds to Layer 3.

### S

- **Sandbox** — execution isolation of Botlets. Four strategies: processes+seccomp, containers, WASM, MicroVMs.
- **Semantic layer** — encodes the meaning of dimensions, facts, hierarchies. Essential for Varnished Kimball.
- **Signage** — passive dashboards without requiring interaction.
- **SME — subject-matter expert** — the human expert whose knowledge is transferred to the agent in Capability construction. Opening workshop and ALPHA validation of Wingtraining.
- **Space / WorkSpace** — human habitat. Reserved for humans.
- **Strategic archetype** — pattern of positioning in the coverage × depth space of the value chain. Four canonical: Comprehensive platform (broad coverage; Core in its native link and Platform in the adjacent ones) · Vertical specialist (focal coverage, Core depth) · Domain infrastructure (zonal coverage, Core in several links) · Substrate provider (minimal coverage, Infrastructure depth).

### T

- **Template** — client-specific tailoring over a **canonical instrument** (report/dashboard) in its own format or rule. **Layer 1 · Interaction.** NOT a Capability nor a Connector.
- **temporality** — regime of the Botlet's manifestation. Declared attribute: **`discrete`** (pulses: schedule/trigger/event) and **`continuous`** (persistent life; mandates the persistent Layer 3 runtime). "Real time" is chosen by giving continuous temporality, not by marking a `push` channel.
- **Three times of the agent** — canonical temporal frame: **Preparation** (mise en place, batch / off-peak), **Attention** (critical path, real time), **Engineering** (bridge, medium term). The parallel topology describes WHERE; the three times describe WHEN.
- **Tokenization** — replacement of sensitive data with tokens before cognition.
- **Tool** — an invocable instrument. Link 9. Canonical protocol: MCP. **NOT a Capability.**
- **Trace** — end-to-end traceability.
- **Transparency** — Pillar 5 of Trust Infrastructure. Understanding in real time **what the agent is doing and why**, with enough detail to intervene. It connects the other four pillars.
- **Tripartite pattern Cloud + Client + Local** — canonical deployment pattern of enterprise Trust Infrastructure.
- **Trust Infrastructure** — five pillars: Governance, Audit, Validation, Resilience, Transparency.

### U

- **ucodex** — proper name of the **proprietary codex** of Grupo Ultra: its private catalog of proto-Botlets, Capabilities, and patterns, curated by real cases over the reference implementation (Vergis). An instance that exemplifies the *proprietary codex* mode; same drawer of proper names as Soveria, Agentia, ultraPRO — not a type of the canon.

### V

- **Validation** — Pillar 3 of Trust Infrastructure.
- **Vergis** — proper name of the public reference implementation of AgencyDomains (the platform; the AgencyDomain made operational). Category: **Meta-Cognitive Platform**. Distributed **AGPL**, public repo, **AgencyDomains.org**. An instance proper name (like Soveria, Agentia, ultraPRO), not a type like Botler.

### W

- **Wingtraining** — canonical development scheme of a Capability in five steps: workshop with the SME · creation · customization · ALPHA · BETA.
- **Wingworking** — collaborative human-AI practice. The methodological frame under which the book was produced.
- **WorkSpace** — see Space.
- **Wrapper / Platform / Core / Infrastructure** — the four canonical depths.

---

## 13 · Reference implementations

The architecture is **product-agnostic**. It admits multiple cooperating implementations.

**Canonical clarification**: the four layers are an X-ray of the individual agent. **They are not slots where a product is assigned to each.**

**Note on the scope of the canon**: this canon contains the structure and the vocabulary of the Agentive World — definitions, primitives, required properties, canonical separations. **It does not contain methods to implement or operational catalogs**: those live in complementary bodies. The public reference implementation is **AgencyDomains.org**, materialized in **Vergis**.

### Vergis — public reference implementation

**Vergis** is the public reference implementation of AgencyDomains — the AgencyDomain made operational. Distributed under **`AGPL`** (code) and **`GFDL`** (docs), public repository at **AgencyDomains.org**, designed to be downloaded, read, run, and learned from to see how the canon translates into living systems. Its full development is **Chapter 9** of the book.

**Naming scheme — type vs proper name**:

| Layer | Type / category | Proper name |
|---|---|---|
| Platform · *Meta-Cognitive Platform* | reference implementation of AgencyDomains | **Vergis** |
| Layer 3 runtime | **Botler** (normed construct of the Botlet spec, generic) | — (no proper name) |
| Catalog component | platform proto-Botlet for informational operation | **Mira** |

- **Botler** is a **type** (a normed construct of the Botlet spec — not one of the eight primitives). Any conformant Layer 3 runtime *is a* Botler.
- **Vergis** and **Mira** are **proper names** of instances (same drawer as Soveria, Agentia, ultraPRO).
- Vergis's category: **Meta-Cognitive Platform** — it administers the **economics of cognition** (G1 pre-forged muscle vs fresh-cognition fallback, `95/4/1` cycle, junior→senior maturation, crystallization). **NOT abbreviated to "MCP"** — that acronym names the Model Context Protocol. The descriptor is used spelled out.

**What it includes**: the abstract contract of the **Botler** (generic, with control points `capability_call`/`log` and validation by delegation) · **Mira** (a platform proto-Botlet operating in `G1`) · a starter set of **Capabilities** and **Connectors** · Trust Infrastructure templates (policies, append-only log, declarative quality contract) · executable examples that walk the chain `use case → Botlets → proto-Botlets`.

**Production grade**: it is the **same runtime** that operates the commercial products (Agentia · Soveria · ultraPRO). The difference from those products **is not the quality of the code but the catalog**: the products consume the public reference **plus a proprietary codex** (ucodex is one exemplar) that curates proto-Botlets, Capabilities, and patterns refined by real cases.

**Adoption model** (replicable without permission or central contract): (1) **consume** the public reference; (2) **curate** its own codex; (3) **offer** its products on that base. AgencyDomains.org is not the property of one actor: it is common ground.

**Common catalog and network effects**: proto-Botlets accumulate in shared catalogs; each consumer contributes to maturation and implementer n+1 receives versions refined by implementers 1..n. Four membership modes: **private contract** · **proprietary codex** · **open public catalog** (AgencyDomains.org) · **sovereign agreement**. The runtime is common; the curation is each one's own.
