← Field notes & protocolsSPECIFIED

Gantry and Capability Leases

Integration and authority firewalls for external tools, models, devices, and agents

Gantry

Gantry is the only lawful composition boundary between canonical state and external systems.

An external connector declares:

connector_id
source_identity
input_schema
output_schema
authority_required
project_scope
privacy
rate/capacity
failure_behavior
retry
idempotency
receipt
revocation
quarantine

A model, API, device, bank, repository, or media provider cannot write canonical state directly.

Capability lease

Authority is granted as a time- and scope-bounded lease:

lease_id
principal
worker
project
object scope
operations
locality
budget
issued
expires
approval
revocation

The runtime enforces the lease. Prompt text cannot expand it.

Transition

request
→ schema validation
→ identity and project scope
→ authority lease
→ privacy and policy
→ optional approval
→ external call
→ normalized Return
→ verification
→ proposed canonical transition
→ receipt

Failure

Gantry must expose:

  • unavailable connector;
  • expired authority;
  • rate limit;
  • partial Return;
  • external contradiction;
  • timeout;
  • invalid signature;
  • quarantine;
  • rollback route.

A silent retry that duplicates a payment or publication is prohibited.

Public doctrine

The model may interpret and propose. Gantry decides whether a crossing is lawful. Canon changes only through the truth system.

This boundary lets providers remain replaceable and protects Project Core from tool-specific memory or permissions.

Source register

  • N04-S01 — MCE-1 System Contract. MCE-1-SYSTEM-CONTRACT-v0.1.md
  • N04-S02 — LM Jefe Full System Specification. LM_JEFE_FULL_SYSTEM_SPEC.md
  • N04-S03 — GlyphCAS Design Report. How_we_can_make_CAS_lightning_fast_for_any_LLM_by_design_or_adaptation.docx