Status
contract + direction
Conceptual layer
④ Decision
Repo layer
L4 knowledge-reasoning
Source
architecture section 3.6.4, section 5.11
ADR
026
Registry owner (direction)
D9
Normative checkpoints
00-kernel.md section 12

The kernel stays small. Domains, workflows, soft thresholds, and model pins change weekly in v1. Hard-coding them into the runtime turns every plant request into a rewrite and breaks replay. Everything replaceable is a versioned registry entry pinned by one release lockfile.

The kernel and runtime refer to registries by id. They never list the five seed domains by name.


Registry catalog#

RegistryWhat an entry definesUsed by
Domainsid, label, attention-budget exempt flag, default owner rolesCard primary domain; memory tags; seam options
FamiliesEvidence family → domain, proof obligations, workflow defaultL3 Evidence intake (as built: Finding)
WorkflowsStage sequence id, applicability predicate, escape to investigativeWorkflow-route seam
StagesStage id, port, allowed tools, token budgetStage graph
AnalysesPlug-in id, domain binding, claim kinds, forbidden claimsDomain analyses
PatternsScanner predicate, footprint template, domain, condition-key recipe, verification recipe, owner, precision thresholdsDiscovery emit
Constraint kindsPredicate vocabulary + evaluator bindingConstraint evaluator
ToolsAllowlisted read tools / builder readsAnalyses, zoom
PromptsVersioned prompt ids per seam / analysisModel calls
Memory missionsHindsight mission ids and retentionPlant bank
Model pinsFamily A/B ids, offline council ids, hosting modeRuntime
Ranking policyLexicographic order for discovery/portfolio rankingDiscovery, portfolio
Soft-gate thresholdsNumeric / enum thresholds per soft gate idSoft gates
RolesOwner role setOne-owner rule

Release lockfile#

One lockfile per deploy pins:

  • every registry entry version in use
  • l4-kernel version
  • model pins
  • Hindsight / case-library schema versions

Replay of a past DecisionCaseOne run unit: intake + snapshot + obligations + candidates + terminal uses the lockfile that was live at run time. Nothing in a registry promotes itself into the lockfile.


Default stage graph#

L4 default stage graph

Default stage graph (registry)

Candidates

Constraint evaluator

Portfolio

Card minimizer

Kernel re-check

Kernel checkpoints
(00-kernel section 12)

↩ Terminal: emit / supersede / withhold / abstain

How to read it.

  1. Registry-defined stages run left to right; custom graphs may add stages but must still hit every kernel checkpoint.
  2. Portfolio and minimizer sit before the kernel re-check; nothing skips the constraint evaluator.
  3. Terminals are code-owned; registries never promote themselves into the lockfile.

Build now: seed registries + default graph above. Later: extra stages that preserve checkpoints (17-change-guide.md).

View Mermaid source
flowchart TB
    %% house-style: l4-default-stage-graph
    subgraph pipe["Default stage graph (registry)"]
        direction LR
        c["Candidates"] --> ce["Constraint evaluator"]
        ce --> pf["Portfolio"]
        pf --> mn["Card minimizer"]
        mn --> kr["Kernel re-check"]
    end
    gate{{"Kernel checkpoints<br/>(00-kernel section 12)"}}
    term(["↩ Terminal: emit / supersede / withhold / abstain"])
    kr --> gate --> term

    classDef govc fill:#fff4d6,stroke:#c99a2e,color:#000
    classDef agentc fill:#e8f0ff,stroke:#5b7bd5,color:#000
    classDef loopc fill:#eef7ee,stroke:#4f9a4f,color:#000
    class gate govc
    class term loopc

Rules that every custom graph must still obey — see 00-kernel.md section 12 (do not restate the checkpoint list here).

Stages may be added (e.g. an optional analysis stage) or reordered within those checkpoints by registry change + replay.


How a new domain appears#

  1. Domain registry entry (id, exempt flag, roles).
  2. Analysis plug-in bound to that id (10-domain-analyses.md).
  3. Memory tag scope uses the same id.
  4. Seam option sets pull domains from the registry — no seam code change.
  5. LockfileRelease pin of registry versions, kernel version, model pins pin + replay on holdouts + shadow before plant default.

No kernel edit. No ADR unless the domain needs a new hard gateNever tunable, never backlog, never explored (unusual).


How a new pipeline stage appears#

  1. Stage registry entry (port, tools, budget, typed in/out).
  2. Insert into workflows without skipping kernel checkpoints. If the stage changes candidates or footprints after the constraint evaluator, it must trigger constraint re-evaluation before portfolio.
  3. Lockfile + replay.

If the stage would change a kernel checkpoint, that is an ADR + kernel bump — not a registry-only change.

Domain registry entry (canonical fields for v1): id, label, attention_budget_exempt, default owner roles, analysis plug-in id. Richer fields (claim kinds, effect units, calculator methods, rendering) live on the analysis plug-in and family entries — see 17-change-guide.md for the full add-domain recipe including L5/L6 section ids on the wire.


Exception-response attention exemption#

Declared on the domain registry entry (attention_budget_exempt: true), not hard-coded in portfolio logic. Portfolio reads the flag (09-portfolio.md).


Seam options from registries#

Workflow route, secondary domain, owner role, pattern id, and similar closed option sets are populated from registries at runtime. Adding a domain or workflow automatically extends the option set for the next lockfile that includes it.


Change control summary#

ChangePath
Registry contentEntry version + lockfile + replay
Soft-gate thresholdSoft-gate registry + owner accept after evidence (22-missed-opportunities.md)
Stage graph shapeStage + workflow registries + replay; must keep kernel checkpoints
Kernel checkpoints / hard gatesADR + kernel version bump + full replay

See also 17-change-guide.md.


v1 slice vs later#

v1Later
Seed registries for five product domains + Pilot families/workflows/patternsSixth+ domains, more stages, more soft gates — still registry-only
Default stage graphCustom graphs that keep kernel checkpoints
Soft-gate thresholds in registrySame; calibrated via opportunity ledger
Shared pack target: stamped-external/registries/ (schemas + seed; implementation after this docs set)Same location
Page history: last 4 changes
  1. 2026-10-07 docs(technical): rewrite l4 21-30, glossary and README; reconcile architecture gaps e7fead7
  2. 2026-10-03 docs(decisions): add ADR-033..038 (twin runtime, fast read path, plant-side writer, message classes, alerts and quality-to-lot link, part-keyed parameters), fast-loop technical set, rebuilt index with renumbering map; fix bare-number link text and ranges 22e2872
  3. 2026-10-03 docs(decisions): renumber live ADRs 001-032 in order, mark withdrawn refs ADR-W###, repoint withdrawn links to archive, note partial supersessions 36c944e
  4. 2026-09-25 docs(l4): agentic decision architecture, ADRs, and production hardness 8275e7c

Diagram

100%

Search the architecture