Gantry and Capability Leases
Integration and authority firewalls for external tools, models, devices, and agents
Gantry
Gantry is the only lawful composition boundary between canonical state and external systems.
An external connector declares:
connector_id
source_identity
input_schema
output_schema
authority_required
project_scope
privacy
rate/capacity
failure_behavior
retry
idempotency
receipt
revocation
quarantine
A model, API, device, bank, repository, or media provider cannot write canonical state directly.
Capability lease
Authority is granted as a time- and scope-bounded lease:
lease_id
principal
worker
project
object scope
operations
locality
budget
issued
expires
approval
revocation
The runtime enforces the lease. Prompt text cannot expand it.
Transition
request
→ schema validation
→ identity and project scope
→ authority lease
→ privacy and policy
→ optional approval
→ external call
→ normalized Return
→ verification
→ proposed canonical transition
→ receipt
Failure
Gantry must expose:
- unavailable connector;
- expired authority;
- rate limit;
- partial Return;
- external contradiction;
- timeout;
- invalid signature;
- quarantine;
- rollback route.
A silent retry that duplicates a payment or publication is prohibited.
Public doctrine
The model may interpret and propose. Gantry decides whether a crossing is lawful. Canon changes only through the truth system.
This boundary lets providers remain replaceable and protects Project Core from tool-specific memory or permissions.
Source register
- N04-S01 — MCE-1 System Contract.
MCE-1-SYSTEM-CONTRACT-v0.1.md - N04-S02 — LM Jefe Full System Specification.
LM_JEFE_FULL_SYSTEM_SPEC.md - N04-S03 — GlyphCAS Design Report.
How_we_can_make_CAS_lightning_fast_for_any_LLM_by_design_or_adaptation.docx