Status
contract
Conceptual layer
④ Decision
Repo layer
L4 knowledge-reasoning
Source
architecture section 3.6.4, section 5.3, section 5.11
Normative
00-kernel.md
ADRs
020 · 025 · 026
Siblings
21-registries-and-stage-graph.md · 12-trace-and-eval.md · 13-improvement.md · 16-operations.md

L4 is built to change at the edges and, when needed, at the core — without rewriting the kernel every time. Almost every expansion is a registry entry, a replay pack, and a new lockfile pin. A few surfaces never move without an ADR.


Purpose#

Give a recipe for each common expansion, say what every recipe shares (registry + replay + lockfile), and draw the line where ADR + kernel bump is mandatory.


Decisions#

#DecisionReason
1Four change classes: data, plug-in, structural, kernelCheap changes stay cheap; rare changes stay rare (ADR-026)
2Every data/plug-in/structural change ships through registry entry → replay → shadow → canary → lockfile pinSame ceremony; different ports
3Kernel refers to registries by id; never lists domains or stages by nameA sixth domain must not require a kernel edit
4Hard gates, terminals, money ownership, and the write ban never change without ADR + kernel version bump + full replayThese are the frozen yardstick (00-kernel.md)

Rejected: silent plant registry edits; free agents inventing stages at runtime; soft-editing hard stops to “catch more opportunities”; blending change classes into one approval path.

Would change this: measured evidence that a surface currently called kernel should be a registry (would need ADR); or that replay suites miss a class of regressions.


Shared path (every recipe below)#

  1. Registry entry — id, semver, status (draft | shadow | certified | retired), scope (global or plant override), owner, dependencies, triggered replay suites, deprecation window.
  2. Replay — candidate lockfile vs pinned lockfile on the required suites (12-trace-and-eval.md). Holdouts the proposers never saw.
  3. Owner pack — plant owner for plant scope; Stamped tech lead for global.
  4. Shadow → canary → pin — (16-operations.md). Unpin rolls back.

No path skips the lockfile. Nothing promotes itself.


Change classes#

ClassWhat movesCode?Ceremony
DataRegistry content onlyNoRegistry + replay + pin
Plug-inNew code behind an existing portYes, behind portPort conformance + data path
StructuralStage graph topology / orderGraph registry releaseMust still hit fixed kernel checkpoints; portfolio after constraint evaluator
KernelTerminals, hard stops, money ownership, write ban, constraint semantics at the gateYesADR + kernel version bump + full replay

Recipes#

Domain#

StepAction
RegistryDomain entry: claim kinds, effect units, evidence/verification types, L3 calculator/verification methods, analysis contract, owner roles, cross-section interactions, portfolio flags (e.g. attention exempt), section rendering spec ref, “sections never summed”
Plug-inDomain analysis behind DomainAnalysis port
SeamsOptions appear from registry ids — no seam code change
L3Methods / detectors as needed via shared pack
L5 / L6Store Prescription sections by id (section 5.3); render from rendering spec
Product framingAdding to the product story still needs ADR-018 amendment; architecture accepts the registry entry now
SuitesPer-domain regression + cross-section conflict + portfolio

Class: data + plug-in. Not kernel.

Family (decision family)#

StepAction
RegistryFamily id, allowed workflows, proof obligations, default owner-role set, condition-key hooks
ReplayFamily holdout suite + terminal accuracy
LockfilePin family version

Class: data.

Workflow#

StepAction
RegistryWorkflow recipe: stages used, seam option bindings, latency tier
ReplayWorkflow suite on held-out DecisionCases
LockfilePin

Class: data (unless it needs a new stage → structural).

Stage (pipeline stage)#

StepAction
RegistryStage id, typed in/out, version, place in stage graph
CheckpointsGraph must still satisfy 00-kernel.md section 12 (constraint → portfolio → minimizer → re-check → terminal). Do not restate or weaken that list here.
ReplayOld graph lockfile vs new graph lockfile
LockfileStage-graph version bump

Class: structural. Changing the checkpoints themselves is kernel + ADR.

Analysis (domain analysis field / plug-in)#

StepAction
RegistryBind analysis id to domain id; declare reads, claim kinds, forbidden claims
Plug-inImplement DomainAnalysis contract
ConformancePort tests: no money invention, no constraint evaluation, citations required
ReplayDomain suite

Class: plug-in (+ data binding).

Pattern (discovery)#

StepAction
RegistryScanner predicate, footprint, domain, condition-key recipe, verification recipe, owner; status starts shadow
PathEmit only when certified; shadow traces otherwise (ADR-022)
Hand-offWhen L3 ships a detector, retire the L4 pattern
ReplayPattern holdout + precision/recall (20-benchmark.md)

Class: data (+ scanner plug-in if new scanner code).

Constraint kind#

StepAction
RegistryPredicate kind, evaluator rule, behaviour on unknown (hard → withhold; never “treat as ok”)
CodeEvaluator in constraint engine — models never evaluate
ReplayAdversarial constraint suite

Class: data + deterministic evaluator code (not LLM). Semantics of hard unknown remain kernel-aligned.

Tool#

StepAction
RegistryTool id, port (ToolAdapter / L3 methods / builder read), allowed callers, least privilege
BanNo equipment write tools; write ban is kernel
ReplayTool contract + grounding tests

Class: plug-in. New write capability = kernel + ADR (rejected in v1).

Prompt#

StepAction
RegistryPrompt id, seam or stage binding, version, ACE/GEPA bullet deps
ReplaySeam calibration + terminal accuracy on holdouts
LockfilePin

Class: data.

Memory mission#

StepAction
RegistryMission id, tags, reflect-only directives, mental-model questions (owner-gated)
WritesTyped only; case library wins on outcome conflict (ADR-021)
ReplayMemory poisoning / negative-memory suites

Class: data (backend swap = plug-in behind MemoryPort).

Model pin#

StepAction
RegistrySlot, provider, family, revision/digest
ReplayDual-family agreement calibration; one-family mode if applicable
OpsShadow → canary → pin (16-operations.md)

Class: data.

Soft-gate threshold#

StepAction
RegistryGate id, threshold, scope, owner (ADR-025)
EvidenceOpportunity ledger scorecard + exploration — both directions (22-missed-opportunities.md)
ReplayThreshold trade-off curves on ledger holdouts
BanHard gates are not thresholds

Class: data.

Ranking policy#

StepAction
RegistryOrdered lexicographic criteria (no blended score); versioned
ReplayPortfolio regret + attention-budget suites
LockfilePin

Class: data.


What requires ADR + kernel bump#

SurfaceWhy
New or removed terminalChanges what L5 may receive
Hard gate set or semantics (hard stops, unknown-on-hard, proof floor, invented-rupee ban, write ban)Frozen yardstick
Money ownership (who may mint a rupee reference)Calculator path only; L3 owns methods
Write ban / equipment actuation from L4HITL; read-default
Constraint evaluation leaving codeModel-as-gate is rejected
Anything that lets emit bypass kernel checkpointsStage graph would stop being safe to expand

Path: write ADR → bump kernel version in 00-kernel.md → full replay across suites → shadow/canary/pin with tech-lead acceptance.


What never changes without ADR#

These are not soft preferences:

  1. Hard gates — not tunable by ledger calibration; wrong hard blocks are data/constraint ownership problems (22-missed-opportunities.md).
  2. Terminals — emit, supersede, withhold, abstain (plus hold as L4-internal, not a terminal to L5).
  3. Money ownership — L3 calculator references only; models never assign rupees or evidence tiers.
  4. Write ban — L4 does not write equipment or schedule; humans execute; L5 records.

Also fixed without this guide’s data path: L2 remains plant source of truth; PSMPlant Situation Model is derived cache; no multi-round debate as the decision mechanism (ADR-020); unknown on hard → withhold; one-card / one-owner rules.


Production hardness (required for product emit)#

Implement and change via ADR-027 docs — not optional “ops later”:

DocSurface
25Queue priorities, caps, dedupe
26Case states, leases, resume
27Port deadlines, breakers, idempotency
28Safe-start, kill switch
29Suites, CI, SLOs, durability

Caps and deadlines are data. Removing safe-start or fail-closed L4Store behaviour needs an ADR.


Worked sketches#

Add a sixth domain#

Shared registry pack gains the domain entry → L3 adds methods/detectors → L4 adds analysis plug-in → seams pick up the id → L5 stores the section id → L6 uses rendering spec → replay domain + cross-section suites → pin. Kernel untouched. Product marketing still waits on ADR-018 if the domain is sold as first-class.

Insert a pipeline stage#

New stage registry entry + stage-graph release → confirm kernel checkpoints still fire in order → replay old vs new graph → pin. Do not put portfolio before the constraint evaluator.

Swap memory backend#

New MemoryPort adapter → conformance tests → same mission registry → replay poisoning/outcome-authority suites → pin. Missions unchanged.

Allow model to override a feeder bound for savings#

Rejected. Hard gateNever tunable, never backlog, never explored. Would need ADR and should not ship.


Doc dependency map (when a surface moves)#

SurfaceUpdate these docs
Domain / family / pattern / constraint kind21, 10, 08, 04, 18, shared registries
Stage graph21, 01, 07, this guide
Soft-gate threshold22, 13, 16, ADR-025
Model pin / seam11, 16, ADR-023
Kernel / terminals / hard gates00, ADR-020, this guide, 19-failure-modes.md
Money / L3 tools15, 18, architecture section 5

v1 slice vs later#

v1Later
Recipes above as the contract; fitness checks stated for CIAutomated fitness CI: no hard-coded domain names outside seed; every stage typed/versioned
Five domains in product framingSixth domain when ADR-018 and Pilot evidence agree

Change class of this document#

This guide is data relative to the kernel: clarifying recipes does not change terminals. If a recipe contradicts 00-kernel.md, the kernel wins until an ADR says otherwise.

Page history: last 3 changes
  1. 2026-10-07 docs(technical): rewrite l4 11-20; reconcile contract deltas with section 5 ef9187f
  2. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  3. 2026-09-25 docs(l4): agentic decision architecture, ADRs, and production hardness 8275e7c

Diagram

100%

Search the architecture