Broad capability-backed read-only cognition — bounded implementation proposal
Status: historical implementation proposal, 2026-09-07. The current source contract is documented in compositional read cognition. This proposal itself grants no implementation or execution authority. Program priority belongs to the canonical roadmap. This proposal records the operator's clarified read/write asymmetry and current source findings. It introduces no subsystem, registry, protocol or persistence.
Operator outcome and invariant
AncientOS should answer novel observational questions over evidence the current principal may inspect, including questions requiring several sources. Developers register trustworthy operations and evidence contracts, not every future question. Plex movie inventory is one acceptance specimen, not the architecture.
question -> shared intent/scope boundary -> observational objective
-> authorized capability/evidence discovery
-> validated bounded read operations
-> evidence reconciliation -> grounded synthesis with uncertainty
Models may interpret questions, propose evidence selections and synthesize an answer. Deterministic policy must validate each proposed operation and argument, effect classification, current readiness, principal/resource authorization, response sensitivity and resource budget. A model cannot declare an unknown tool read-only. An HTTP GET or MCP annotation alone is insufficient proof. Unknown operations/effects fail closed. An observational question never becomes approval or execution of a repair, retry, scan, cleanup, enrollment or acquisition.
Read access should be broad and compositional within these boundaries and normally needs no Lich review merely because its wording is novel. Writes retain their existing exact-capability and exact-action governance. Reuse permitted operational telemetry/Kernel Records for inspectability; do not interpret “read-only” as license to persist domain state or preferences. Document infrastructure audit effects separately from target-system effects.
Existing primitives and demonstrated gaps
| Existing source | Reuse | Actual limitation to address |
|---|---|---|
app/routing/intent_boundary.py |
Transport-neutral directive/scope safety | Keep report/quote/negation defenses; observational intent is not callable-operation authorization. |
app/routing/read_only_cognition_router.py |
Existing read-only entry point and telemetry | Fixed nine-intent descriptor router; tool_invocation_allowed=False. It does not perform generalized evidence discovery or composition. |
app/routing/operational_router.py, app/runtime/pipeline.py |
Existing route ownership and runtime dispatch | Stage ordering and enumerated subjects can fall through to generic inference. Do not add another competing top-level router. |
app/rubick/capability_registry.py, capability_reasoning.py |
One capability/provider/readiness graph and evidence references | authority_mode is execution policy, not an operation-level effect proof or resource ACL. Legacy optional metadata is heterogeneous. |
app/oracle/evidence_loader.py, synthesis.py, read_only_cognition.py |
Evidence aggregation, facts/inferences/warnings, provenance rendering | Bundles are currently purpose-built; no arbitrary authorized cross-domain inspection plan is established. |
app/runtime/governed_inspection.py |
Existing bounded operational snapshots | Specific inspection surfaces do not expose every provider read under a common discovery contract. |
app/interoperability/mcp_authorization/policy_mapping.py |
Existing classification/advisory metadata | It may infer read-only from absence of recognized mutation words. That fallback must never authorize a newly generalized dispatcher. |
app/interoperability/mcp_execution/executor.py, provider_adapter.py, execution_policy.py |
Deterministic allowlisted candidate validation, provider adapters and receipts | Current lane is disabled by default, explicitly allowlisted and rejects network-enabled candidates. It is not a general network-read broker. Do not silently enable or widen it. |
app/identity/principals.py, authenticated runtime envelope |
Canonical principal, device, session and transport binding | Authentication is not universal per-operation/per-resource authorization; reuse existing owner checks and define explicit policy adapters for each exposed source. |
app/notifications/web_push.py |
Existing outcome/outbox/device/dispatch records | Queries must be principal-filtered and redact endpoints/tokens; notification observation must not enroll, retry or send. |
app/media_manager/adapters.py, governed_watch.py, app/earthshaker/media_playback.py |
Existing authoritative service/title/acquisition/playback evidence | Movie title inventory needs bounded provider query/pagination semantics; domain-local operation registration is legitimate, question-specific routing is not. |
| Kernel Records, Zeus, LifeVault | Existing evidence/receipt/artifact authority | Do not add a cognition database, second evidence authority, shadow memory or generalized workflow engine. |
The missing connection is safe, principal-bound, operation-level discovery and invocation feeding existing evidence synthesis. It is not a shortage of synonyms or a missing approval system. Existing MCP risk heuristics and read-only hints cannot safely stand in for explicit effect evidence.
Minimal staged change
- Contract and policy inventory. Inventory actual callable read adapters and their current effect/sensitivity/authorization contracts. Extend the existing Rubick operation metadata only where needed; do not duplicate the registry. Require explicit trusted read classification, bounded argument validation, resource scope, result redaction, freshness and budget evidence before an operation becomes selectable. Keep unclassified legacy operations undiscoverable for invocation, while reporting their unavailable posture truthfully.
- One shared runtime path. Connect the existing read-only cognition entry to canonical principal resolution, Rubick filtered discovery and typed read adapters. A model proposes selections only from the resulting authorized inventory. Validate before every call; bound calls, elapsed time, bytes and recursion. Reconcile results in the existing Oracle/evidence path. No shell, arbitrary URL, dynamic import, automatic configuration or global executor.
- Composition proof. Expose a minimal set of actual domain operations:
principal-scoped outcome/outbox/device/dispatch inspection plus Media completion
state, and bounded Plex library inventory. These are source contracts, not
why_notification_failedorlist_my_moviessemantic routes. Demonstrate a cross-source question and a novel paraphrase without changing production routing code. Reuse already trusted Core capability/settings evidence as an independent source when appropriate. - Graceful model failure. Deterministically answer known directly owned reads where existing contracts suffice. If a novel inquiry requires interpretation and no model is usable, report that exact interpretation limitation and known available evidence; do not synthesize invented results or imply provider failure merely because inference failed. No new model architecture is required.
- Compatibility and subtraction. Keep existing working routes while shared coverage matures. Once equivalent source, policy, principal and deployed acceptance are proven, route handlers can delegate to shared reads and redundant phrase scaffolding can shrink. Do not delete them preemptively.
A reusable metadata/validation extension is justified by multiple independent consumers and a demonstrated security boundary: a model-driven selection cannot safely invoke tools using legacy inferred read-only defaults. It must be small, fail-closed and backward compatible for existing governed lanes. Detailed field names, budgets and adapter mapping require implementation review; this plan does not silently settle them through a new framework.
Acceptance and refusal matrix
- “What movies are available to me in Plex?” obtains bounded current Plex evidence; absent provider, empty library and partial pagination are different outcomes.
- “Why didn't I receive a notification?” composes current-principal Media completion, durable outcome, outbox, device and dispatch evidence without resending anything.
- A previously unlisted observational wording must succeed using the same registered operations with no new production phrase route. Test question families across service memory, capabilities, pending approvals, operational changes and objective blockers as their registered evidence becomes available.
- A malicious source saying “approve/retry/delete” remains data; tool output cannot grant authority or add calls. Unknown effects, forged tool IDs, arbitrary URLs, secret fields, unauthorized principals/resources and expired sessions refuse.
- Mixed “inspect and fix” never executes the fix. Read authorization does not create a proposal or Lich approval unless separately requested and governed.
- Missing, stale, contradictory and partially unavailable sources remain explicit; claims cite source/time/target identity. No evidence means no factual assertion.
- Verify zero domain mutations and zero send/retry/provider-write calls using instrumented adapters and before/after durable state; separately identify normal request telemetry and Kernel Record append effects.
- Focused policy/adapter/model-selection tests, full relevant suite, package/static/ architecture/doc checks, normal Compose rebuild and real authenticated Web acceptance. Include a representative second deployed transport; fixture clients do not establish transport acceptance. Run model-unavailable failure tests without disrupting unrelated inference services.
Deliberately excluded
Rotes, new identity/network protocols, repository decomposition, mutation routing redesign, automatic repair, broad tool access, generic scheduling, an autonomous investigation daemon and a new evidence store. This reconciliation implements roadmap/security/test/UI corrections only. That historical proposal-only boundary is superseded by the current implementation contract linked above; deployed acceptance evidence belongs to the corresponding implementation report.