Skip to main content
LAKANA Sovereign Systems Physics-first protection without surveillance
LAKANA Sovereign Systems Architecture

Separate authorities. Clear human interfaces. No hidden handoffs.

LAKANA separates survival, environmental truth, physical admissibility, domain interpretation, custody, responder coordination and public evidence so no single component can observe protected state, interpret it, release it and justify the resulting claim by itself. Every system has a bounded responsibility, a visible refusal state, an identified human interface, and separately stated evidence and operational maturity. Where a source specification described something more dramatic than what is actually built or tested, this page says so directly instead of quietly upgrading the claim.

Reviewer start paths: Safety and emergency reviewer Structural and athlete-safety reviewer Environmental and agronomic reviewer Governance and evidence reviewer

10Bounded components
7Operational authority types
3Independent operational lanes
1Operational governance rail
1Public evidence-adjudication perimeter

Ten bounded components. Seven operational authority types. Three independent operational lanes. One operational governance rail. One public evidence-adjudication perimeter.

These counts describe the architecture's structure, not a deployment count. Individual capabilities carry separately stated evidence and operational maturity throughout this page — see Maturity and evidence classes. Public equations describe governing mathematical form, state classes and authority boundaries. Exact coefficients, thresholds, timing policies, sensor-fusion weights, key-derivation contexts, hardware mappings, private datasets and reconstructive implementation details remain protected.

LAKANA Core

The governing root, the survival substrate, the two conditionally invoked cross-domain authorities, and the public evidence-adjudication perimeter. Everything in the three operational lanes — SOS, SSI, and W-X/WX-Ag — runs on top of what is defined here.

Refusal-state contract — what this design refuses to do
  • Does not infer or advertise unavailable capability
  • Does not authorize unsupported release
  • Does not convert simulation into field validation
Sovereign Root
      ↓
CivilizationOS
      ↓
Conditionally invoked operational authorities
├── TSARO
└── NICOLE Protocol

Independent operational lanes
├── SOS → Blue Force Bridge → optional Tactical Audio Bridge
├── SSI
└── W-X → optional WX-Ag

Public-safe released artifacts
      ↓
SSES evidence-adjudication perimeter
      ↓
Proof Library

Canonical terminology registry

Every acronym on this page is defined here before it is used in depth. Where an earlier internal specification used different wording, this page uses the current public canonical term and documents the older wording only in the implementation report, not in ordinary page copy.

CivOSSubstrate
CivilizationOS

The sovereign survival and execution substrate that manages hardware access, power, local storage, transport availability, degraded operation, and offline preservation.

SOSCoordination
Safety Operating System

The civilian-safety and bounded responder-coordination domain operating above CivilizationOS. Not "Sovereign Operating System."

SSIConsequence
Sovereign Structural Intelligence

LAKANA's structural-intelligence and human-reliability domain for athlete and worker load, recovery, thermal pressure, impact, gait, asymmetry, burden, and role-bounded output.

Legacy dossier alias: "Sovereign Sports Intelligence" — superseded because the current research program extends beyond sports analytics into occupational load, human reliability, and burden governance.
PSSPDoctrine, not a component
Physics-Sovereign Safety Paradigm

The governing safety doctrine under which physical constraints, burden, structural state, uncertainty, and human sovereignty take priority over optimization. PSSP is the paradigm SSI operates under — it is not itself a system domain, and it is not counted among the 10 bounded components.

TSAROAdmissibility
Threat-Adaptive Safety Response Orchestrator

The deterministic physics and admissibility authority that checks whether a state, action, or proposed transition remains within the applicable safe envelope.

NICOLECustody
NICOLE Protocol — Non-Interactive Cryptographic Oversight & Ledger Enforcement

The cryptographic governance, identity, consent, access, lease, revocation, custody, release, and accountability protocol.

BFBResponder workspace
Blue Force Bridge

The responder-facing SOS workspace through which authorized emergency personnel receive bounded incident, route, muster, accountability, triage, and handoff information.

TABFeature inside BFB
Tactical Audio Bridge

The separate consent-gated audio-request feature inside the Blue Force Bridge. Not a standalone system, not a peer of BFB, not a separate authority, not a universal output path, and not automatically granted by BFB access.

W-XTruth
Weather Exchange

The environmental truth, freshness, consistency, uncertainty, and temporal-validity layer.

WX-AgConsequence
Weather Exchange Agronomic Extension

The field-facing agronomic extension that turns W-X-supported environmental state into bounded soil, water, crop, root-zone, evapotranspiration, saturation, anoxia, heat, cold, and agronomic-stress interpretations. Not an independent weather authority.

SSESEvidence-adjudication perimeter
Sovereign Structural Evidence Stack

The eight-model post-run evidence-governance system that determines what a completed artifact may support publicly. The domain model creates the result. SSES adjudicates what the completed public-safe artifact is allowed to support publicly.

Doctrine: why LAKANA separates authorities instead of building one smart system

LAKANA is not a single model with one set of permissions. It is a stack of narrow authorities, each one able to decide only the specific question it was built to answer, required to fall silent or fail closed outside that question, and required to log every decision to a custody-scoped audit trail. This separation is the entire point: a system that only ever answers the question in front of it is far easier to bound, review, and refuse than one system that tries to know and decide everything at once. The layout below exists to make that separation visible, not to make the system look more impressive than it is.

Failure 1 · Silent wrongness

Treating stale, missing, or unverifiable sensor and location data as if it were still current fact.

Avoided by: W-X truth admissibility + fail-closed expiry
Failure 2 · Confident overreach

A model recommending or taking an action it cannot actually show is safe under current uncertainty.

Avoided by: TSARO safe-set contraction, fail-closed default
Failure 3 · Unbounded access

One role, login, or integration having standing, unscoped visibility into everyone's sensitive state.

Avoided by: NICOLE Protocol role/scope/consent/epoch custody gate
Failure 4 · Claim inflation

Public language quietly promising more certainty, safety, or capability than what was actually tested.

Avoided by: Sovereign Structural Evidence Stack (SSES) claim discipline + maturity labels

Architecture in one view

Sovereign Root and CivOS form the shared foundation everything else runs on. Above that, LAKANA splits into independent operational lanes — SOS, SSI, and the environmental lane (W-X feeding WX-Ag) — so a failure or contradiction in one lane does not stall the others. SOS does not require SSI or WX-Ag to run, and neither of those requires SOS. NICOLE Protocol is the one governance rail that operates across every lane: any release of protected, personal, custody-sensitive or role-scoped state, from any lane, is custody-gated by NICOLE Protocol before it reaches a human — it appears as a step inside each lane below, not as a separate stage bolted on top. It does not imply that every public environmental observation requires personal consent governance. SSES sits outside the operational lanes entirely, as a perimeter a lane's output may optionally cross only when it is being turned into a public artifact; a responder packet, a private athlete result, or a local field manifest never goes near it unless someone chooses to publish it. Every chip below is a real link to that component's full chapter.

Shared foundationEverything below depends on this being valid
SOS laneCivilian safety coordination
  1. Incident observation
  2. Relevant physical / environmental validation
  3. TSARO incident admissibility
  4. SOS minimized incident state
  5. NICOLE Protocol scope / release
  6. Optional: BFB handoff↳ optional TAB audio request, inside BFB
SSI laneStructural-load intelligence
  1. Local body / load sensing
  2. SSI structural computation
  3. TSARO safety-envelope evaluation
  4. Minimized role-specific output
  5. NICOLE Protocol user / coach / clinical / research scope
Environmental laneW-X → WX-Ag
  1. Environmental observations
  2. W-X freshness, agreement, physical consistency, drift, TTL
  3. Optional: WX-Ag field / crop consequence
  4. TSARO bounded admissibility for any proposed output
  5. NICOLE Protocol sharing / release policy where scoped
Public evidence laneOptional — only for material being published
  1. Any public-facing artifact from any lane
  2. SSES evidence classification
  3. Maturity label
  4. Limitations
  5. Claim boundary
  6. Publication
Shared-foundation band — Sovereign Root and CivOS. Every lane needs this to be valid, but the lanes above it do not depend on each other.
Lane column — an independent operational path (SOS, SSI, environmental). Each runs its own sequence; none of the three requires either of the others to complete.
Purple governance strip — NICOLE Protocol. Governs access and release inside every lane operationally; it is not a separate top-level stage.
Dashed evidence lane — SSES. A perimeter, not a gate: only material someone chooses to publish crosses into it.
Numbered step, not amber — a required gate. The lane cannot proceed past it without a real evaluation.
Amber-tinted step — an optional branch, taken only when its specific condition applies (for example, TAB inside BFB).
Human interface — see How information reaches the correct person for which device each role actually uses.

How LAKANA information reaches the correct person

Illustrative interface architecture — not a production screenshot.

"Delivery" does not always mean emergency delivery. Every domain below has its own human recipients, its own interface, its own device expectations, its own scope limits, and its own release conditions — a coach's tablet view is not a smaller version of the athlete's phone view, it is a different, narrower authorization entirely.

Safety Operating System

Civilian or protected user
PhoneTabletSupported wearable interface
  • Incident status and safety state
  • Local preservation status
  • Route or muster information
  • Responder handoff status
  • TAB request with accept/deny controls
  • Active TAB session, disconnect, revoke
  • Delivery failure and offline preservation state
The civilian does not operate the Blue Force Bridge as their ordinary personal view.
Refusal/expiry states: preserved-locally (not delivered), denied, expired — always visibleGoverning authority: SOS · NICOLE ProtocolOpen live surface
Emergency personnel (BFB)
BFB responder tabletDesktop/workstationField display where supported
  • Bounded rescue packet and scene state
  • Hazard context, muster points, egress and approach routes
  • Accountability categories, triage/priority state
  • Handoff status, audit history, expiration state
  • TAB request control
The Blue Force Bridge is the emergency crew's SOS environment, not the civilian's.
Refusal/expiry states: lease expiry, stale/unavailable view, no packet without clearanceGoverning authority: SOS coordination · TSARO admissibility · NICOLE Protocol scopeOpen live surface
TAB audio session
Responder's BFB panelUser's phone/tablet
  • Responder selects "Request Audio" inside BFB
  • Request reaches the user's device with a clear announcement
  • User accepts or denies; no audio opens from the request alone
  • NICOLE Protocol verifies scope before an ephemeral session opens
BFB access is not TAB authorization.
Refusal/expiry states: pending, denied, disconnected, revoked, expiredGoverning authority: NICOLE Protocol — a separate, time-boxed lease inside BFBOpen live surface

Sovereign Structural Intelligence

Athlete or worker
PhoneTabletDesktop
  • Personal structural state, load, recovery reserve
  • Thermal pressure, impact burden, gait/asymmetry state
  • Confidence/quality and expiration state
  • Personally owned history
  • Explanation of any withheld result
Receives the richest personally authorized view — nothing here is shown to any other role by default.
Refusal/expiry states: proxy withheld on weak input; expiration state visibleGoverning authority: SSI · NICOLE Protocol self-scopeOpen live surface
Coach or supervisor
TabletDesktop
  • Bounded summary and team/group aggregate
  • Workload envelope
  • Availability state where authorized
No unrestricted raw biological history, no unrelated medical information, no permanent access merely from job title.
Refusal/expiry states: denied beyond authorized scope; envelope summaries onlyGoverning authority: NICOLE Protocol coach scopeOpen live surface
Medical or training staff
TabletDesktop
  • Clinically relevant derived state
  • Requires valid role, valid purpose, scoped lease, time limit
  • Revocation and expiration state visible
Medical access does not convert SSI into a medical authority — clinical judgment stays human and professionally governed.
Refusal/expiry states: lease expiry and revocation always visibleGoverning authority: NICOLE Protocol medical/training leaseOpen live surface
Researcher
Proof Library / Papers
  • Public-safe aggregate
  • Privacy-protected, claim-bounded artifact
No raw subject entitlement.
Refusal/expiry states: aggregate only; no raw entitlement ever grantedGoverning authority: NICOLE Protocol aggregate scope · SSES perimeterOpen live surface

Weather Exchange & WX-Ag

Environmental operator — W-X environmental truth
PhoneTabletDesktopLocal node interface
  • Observation, unit, source class, observation time, age, TTL
  • Agreement, physical-consistency state, drift, uncertainty class
  • Authority state, quarantine, expiration, silence
Refusal/expiry states: degraded, contradictory, drifting, quarantined, expired, silentGoverning authority: W-X Truth AuthorityOpen live surface
WX-Ag — field operator or farmer
PhoneTabletDesktop
  • Field zone, soil state, root-zone water, ET₀, VPD
  • Saturation, anoxia proxy, heat/cold pressure, crop-stage context
  • Water deficit, uncertainty, source class, advisory boundary
WX-Ag provides bounded descriptive and advisory context — it does not become the farmer's decision authority.
Refusal/expiry states: consequence withheld when the underlying truth is inadmissibleGoverning authority: WX-Ag under W-X admissibility · NICOLE Protocol manifest ledgeringOpen live surface

Cross-cutting status, shown inside each domain interface

CivilizationOS, TSARO, and NICOLE Protocol are not separate consumer applications a person opens on their own. Their state appears inside whichever domain interface is active.

CivOS-visible states
NormalReduced powerLocal-onlyStore-and-forwardTransport unavailablePreservation activeEmergency minimumUnavailable
TSARO-visible states
AdmissibleHeldDegradedQuarantinedBlockedFail-closedSilent
NICOLE Protocol-visible states
AuthorizedScope-limitedPendingDeniedRevokedExpiredPreserved, unreleasedAudit-recorded

Seven questions LAKANA answers

Every chapter below exists to answer exactly one of these seven questions. If a question isn't on this list, no LAKANA authority is trying to answer it — that is deliberate, not an oversight.

1. Is the system even able to run right now?

Answered by Substrate Authority. Before anything else happens, CivOS has to confirm there is enough power, storage, and transport to operate — and to enter a degraded mode honestly if there isn't.

See the CivOS chapter →

2. What do we actually, verifiably know right now?

Answered by Truth Authority. W-X decides whether an environmental reading is fresh, physically consistent, and corroborated enough to be treated as real — and lets it expire to silence instead of staying "true" forever.

See the W-X chapter →

3. What does that truth mean for this body or this field?

Answered by Consequence Authority. SSI turns environmental and load truth into a structural pressure proxy for a person; WX-Ag turns it into a burden proxy for a field. Neither one tells you what to do about it.

See the SSI chapter →

4. What is physically safe to do about it?

Answered by Admissibility Authority. TSARO checks whether the current or proposed state stays inside a defined safe set. If it can't confirm that, it fails closed — it does not guess.

See the TSARO chapter →

5. Who is actually allowed to see or hold this?

Answered by Custody Authority. NICOLE Protocol checks role, scope, consent or lease, time window, and revocation status before anything is released, and logs the decision either way.

See the NICOLE Protocol chapter →

6. How does a human get bounded safety help?

Answered by Coordination Authority. SOS presents bounded safety state directly to the user's own phone, tablet, or supported wearable interface. Separately and optionally, once TSARO and NICOLE Protocol clear it, a minimized packet may also reach a responder through the Blue Force Bridge (BFB) — the responder-facing workspace, whose Tactical Audio Bridge (TAB) feature can separately open a consent-gated audio session inside it.

See the SOS chapter →

7. What is LAKANA actually allowed to say about all of this, in public?

Answered by the Public Evidence Adjudication Perimeter — SSES — feeding the Proof Library. A result doesn't get published just because it exists — it has to carry a maturity label and its non-claims.

See the SSES chapter →

Authority model — 7 authority types

Every one of the 10 components below belongs to exactly one of these seven authority types. The type is what actually determines what a component is allowed to decide — the name is just a label. BFB and its TAB feature share one authority type and one component; TAB is not counted separately.

Authority typePlain-language questionHolds this authorityWhen it says no
ConstitutionalWho consents, and what governs every downstream boundary?Sovereign RootNo observation occurs.
SubstrateCan the system run at all right now?CivOSDegraded/local-only mode; no higher-layer output.
TruthWhat is physically, verifiably real right now?W-XReading decays to null instead of staying "true."
ConsequenceWhat does that truth mean for this body or field?SSI, WX-AgProxy is withheld rather than estimated on weak input.
AdmissibilityIs this action physically safe under current uncertainty?TSAROFail-closed / silence — TSARO's default behavior.
CustodyWho is allowed to see, hold, or receive this?NICOLE ProtocolRelease denied by default; the denial itself is logged.
CoordinationHow does bounded safety state reach the user, and optionally a responder?SOS, BFB (including BFB's TAB feature)Nothing is delivered; no channel opens.

Complete system chapters

All information about one system is grouped into one complete chapter — you should never need to assemble one system's meaning from six distant parts of this page. Every chapter follows the same structure and, where the underlying capability is not yet built or tested, says so in the maturity field rather than upgrading the claim.

Public-safe math and trade-secret boundary: every equation shown on this page describes governing mathematical form only. Exact coefficients, thresholds, weights, and tuning constants are protected trade secrets and are not disclosed on this page, on any linked simulation, or in any linked evidence artifact.

GOVERNING ROOT · Constitutional Authority

Sovereign Root

The policy and identity root that establishes consent, revocation, purpose, role boundaries, user-configured emergency doctrine, and non-negotiable limits for personal or protected state — not a single binary switch that blocks all system behavior without a fresh consent record.

Constitutional AuthorityArchitecture DoctrineCustody / Lease Metadata
Hard boundaryMay not decide any physical, environmental, or structural fact (no sensors, computes nothing); block device-integrity or hardware-health checks, which may run without exposing personal content; gate non-personal environmental-infrastructure observation, which is not personal-consent-scoped at all; or override physical law, applicable law, another person's rights, or a safety boundary.
Human endpointThe user configures this directly on their own phone, tablet, or desktop; see how information reaches the correct person for every downstream role.
Strongest non-claimNot a legal contract, not a court-enforceable agreement on its own, not a substitute for applicable consent or privacy law, and not a claim that every device or infrastructure behavior requires a fresh personal-consent check.
Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
The policy and identity root that says what a person has consented to, what they have pre-authorized in advance, what purposes and roles are in bounds, and what limits are non-negotiable — for personal or protected state specifically, not for every internal system behavior.
Why it exists
Without a root of authority, the provider, employer, institution, team, platform, insurer, or network operator can become the de facto owner of a person's information.
Real-world failure it prevents
A "helpful" system observing, modeling, or acting on a person's protected state without agreement, or continuing after consent has been withdrawn — while still letting the system do its basic job.
Authority it owns
Whether personal observation, modeling, or release of protected state is covered by valid policy authority right now — either standing consent or a pre-authorized bounded rule the user configured in advance — and whether a result may ever reach a public claim.
Inputs
Explicit consent and agreement records, institutional agreements, user-configured pre-authorized emergency doctrine, revocation requests.
Governing mechanism
A policy-authority evaluation: standing consent, a matching pre-authorized rule, or neither.
Outputs
A policy-authority decision — standing, pre-authorized, or absent — consumed by NICOLE Protocol at every access and release point for personal or protected state.
Human recipient / device
The user configures this directly on their own phone, tablet, or desktop; see how information reaches the correct person for every downstream role.
What it may do
Grant, withhold, or pre-authorize bounded personal/protected-state processing; set non-negotiable limits; revoke at any time.
What it may not do
Decide any physical, environmental, or structural fact (no sensors, computes nothing); block device-integrity or hardware-health checks, which may run without exposing personal content; gate non-personal environmental-infrastructure observation, which is not personal-consent-scoped at all; or override physical law, applicable law, another person's rights, or a safety boundary.
Dependencies
None upstream — this is the root of the authority stack for personal and protected state.
Components it constrains
NICOLE Protocol, which mechanically enforces the applicable policy; every other component indirectly, wherever it touches personal or protected state.
Components that constrain it
None — applicable law and another person's rights bound it externally, not any other LAKANA component.
Normal operation
A standing consent or matching pre-authorization is on file; NICOLE Protocol enforces it at each access/release point without further Sovereign Root involvement.
Degraded operation
Ambiguous or partially expired policy narrows to the most conservative interpretation still on file, rather than the broadest one.
Adversarial / conflicting-input behavior
A request that conflicts with the on-file policy, or that tries to invoke a pre-authorization outside its declared scope, is treated as unauthorized — not resolved in the requester's favor.
Public-safe implementation pattern
Consent/pre-authorization record → policy-authority check → pass/fail signal to NICOLE Protocol. No physical computation occurs at this layer.
Protected implementation boundary
Exact policy-storage format, internal record schema, and any device-level key material remain undisclosed.
Current implementation
Expressed today as the claim-boundary and consent language across the site, not as a standalone running service with its own telemetry.
Maturity / evidence state
Architecture Doctrine.
Public non-claims
Not a legal contract, not a court-enforceable agreement on its own, not a substitute for applicable consent or privacy law, and not a claim that every device or infrastructure behavior requires a fresh personal-consent check.
Open related simulation
None directly — Sovereign Root is doctrine, not a simulated engine.
Open related evidence
Claim-boundary and consent language on reviewer-access.html and the Background IP & Claim Boundary section of sos-civos-proof-theater.html.
Canonical fragment ID
#sovereign-root
Real-world scenario analogue
Pre-authorized emergency preservation
Situation
A user pre-authorizes SOS to preserve a bounded emergency packet locally during loss of consciousness, but does not grant permanent institutional access.
Human actor
The user, configuring policy in advance; later, an emergency responder.
Device / interface
User's phone at configuration time; BFB responder tablet at incident time.
What is observed
A distress state matching the pre-authorized trigger condition.
What LAKANA computes
Whether the live event matches the declared scope of the pre-authorization.
Which authority evaluates it
Sovereign Root policy, enforced by NICOLE Protocol; TSARO evaluates the incident's physical admissibility in parallel.
What is shown
CivOS preserves the packet locally; if release conditions are met, BFB receives only the pre-authorized scope.
What is withheld
Anything outside the declared scope — a BFB packet pre-authorization does not extend to a TAB audio session, which still needs its own separate authorization.
What action LAKANA takes
Preserve, evaluate, and release only the pre-authorized scope; deny anything broader.
What remains a human decision
Whether to configure a pre-authorization at all, and its exact scope.
Failure behavior
An ambiguous or expired pre-authorization is treated as absent, not as broad consent.
Current evidence level
Architecture Doctrine / Engineering Specification.
What would require field validation
Real incident testing of the trigger-matching logic under actual emergency conditions.
Test this scenario
Not independently testable in isolation — see the SOS chapter's structure-fire walkthrough, which exercises the same NICOLE Protocol enforcement path.

Public non-claim: sovereignty is bounded authority, not unlimited unilateral control.

SURVIVAL SUBSTRATE · Substrate Authority

CivilizationOS (CivOS)

The sovereign survival substrate beneath every LAKANA domain: hardware access, power, local storage, transport availability, degraded operation, and offline preservation.

Substrate AuthorityEngineering SpecificationInfrastructure telemetry only
Hard boundaryMay not determine whether environmental information is true, determine medical meaning, grant institutional access, decide whether a public claim is supported, or replace SOS or TSARO.
Human endpointCivOS state is not a standalone consumer app — it surfaces inside whichever domain interface is active. See cross-cutting status presentation.
Strongest non-claimNot certified emergency hardware, not a guarantee of uptime, not validated for real-world deployment.
Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
The layer that decides whether there is enough real infrastructure — power, storage, transport — to run anything above it, and which degraded mode to enter if not.
Why it exists
Normal applications assume stable power, stable network, a working operating system, available cloud, storage, sensors, and transport. Safety infrastructure cannot assume any of that.
Real-world failure it prevents
A system silently continuing to "act smart" after the power, storage, or transport underneath it has actually failed.
Authority it owns
Whether the platform has sufficient substrate state to operate, and which degraded mode (if any) applies.
Inputs
Battery/power source, device integrity, sensor state, storage state, network/transport state, environmental stress, incident priority, preservation requirements.
Governing mechanism
Assess resources → classify operating mode → prioritize essential capability → preserve critical state → expose honest availability → refuse unsupported transport claims.
Outputs
Power mode, sensor schedule, storage mode, transport mode, local-only state, store-and-forward state, preservation state, an available-capability manifest — consumed by every lane built on top of it.
Human recipient / device
CivOS state is not a standalone consumer app — it surfaces inside whichever domain interface is active. See cross-cutting status presentation.
What it may do
Reduce nonessential sampling, prioritize critical sensors, preserve state locally, delay transport, select available transport, terminate nonessential processing, refuse unsupported behavior.
What it may not do
Determine whether environmental information is true, determine medical meaning, grant institutional access, decide whether a public claim is supported, or replace SOS or TSARO.
Dependencies
Sovereign Root (consent to run at all); TSARO can force fail-closed regardless of CivOS's own assessment.
Components it constrains
W-X, SSI, WX-Ag, SOS, NICOLE Protocol, SSES — every lane needs a running substrate to operate on, independent of whether the other lanes are healthy.
Components that constrain it
TSARO can force CivOS into fail-closed independent of CivOS's own self-assessment.
Normal operation
Full sensor schedule, full transport, no preservation-only mode.
Degraded operation
Reduced power → local-only → store-and-forward → emergency minimum, each honestly exposed rather than hidden behind a claim of normal service.
Adversarial / conflicting-input behavior
Conflicting integrity signals (e.g. a sensor reporting outside physical bounds) route to reduced trust in that sensor, not to silently discarding the conflict.
Public-safe implementation pattern
Resource-bound capability: AvailableCapability(t) = f(power, storage, sensor availability, transport, integrity). Proprietary thresholds inside f are not disclosed.
Protected implementation boundary
Confidential concepts involving custom hardware, analog wake circuitry, isolated micro-VMs, specialized RF behavior, or energy harvesting are Provisional/R&D — exact trigger values and security logic are not disclosed.
Current implementation
Substrate and degraded-mode sections of sos-civos-proof-theater.html — architecture demonstration, not certified hardware.
Maturity / evidence state
Engineering Specification / Architecture Demonstration.
Public non-claims
Not certified emergency hardware, not a guarantee of uptime, not validated for real-world deployment.
Open related simulation
sos-civos-proof-theater.html substrate/degraded-mode sections.
Open related evidence
proof-library.html.
Canonical fragment ID
#civos — preserved; 17 other pages link here.
Substrate state: S(t) = f(power, storage, transport, sensor availability, degraded mode)
Real-world scenario analogue
Degraded-connectivity emergency
Situation
A user is in a degraded-connectivity emergency; the network becomes unavailable.
Human actor
The civilian user.
Device / interface
User's phone or tablet.
What is observed
Transport unavailable, power constrained.
What LAKANA computes
Available capability given current power, storage, and transport.
Which authority evaluates it
CivOS classifies the operating mode.
What is shown
An honest "local-only / preserving" state, not a false "delivered" state.
What is withheld
Any claim of successful transmission that did not actually occur.
What action LAKANA takes
CivOS preserves state locally; SOS does not claim delivery; BFB remains unavailable until transport exists; NICOLE Protocol records the preservation state.
What remains a human decision
Whether and how the user seeks help through other means while transport is unavailable.
Failure behavior
Local preservation, not fabricated continuity.
Current evidence level
Public Simulation.
What would require field validation
Real degraded-network conditions across varied hardware.
Test this scenario
Open SOS + CivOS simulation.

CivOS Energy Discipline

CivOS converts device power, battery health, thermal state, memory, sensing, compute, storage and abstract transport availability into an explicit operating mode. Capability contracts as resources decline; unavailable capability is shown rather than inferred.

Refusal-state contract
Capability reducedTransport unavailableLocal preservation activePlatform suspendedIntegrity unavailableExplicit silence
Formal public energy contract — state space, transition, dictionary, boundary

State space. The public energy state is a nine-dimensional vector:

s_t^energy = [ b_t, h_t, θ_t, m_t, v_t, c_t, a_t, ρ_t, σ_t ]ᵀ ∈ S_energy

Variable dictionary.

  • b_t — normalized available battery energy
  • h_t — battery-health or discharge-capability class
  • θ_t — thermal state
  • m_t — memory and local-storage availability
  • v_t — available sensor-capability vector
  • c_t — compute budget
  • a_t — abstract transport availability
  • ρ_t — incident or safety-relevance class
  • σ_t — CivOS operating mode

Input space. Public resource-input classes: power state, thermal state, storage state, memory state, sensor-availability state, platform-execution state, transport state, incident priority, and user policy.

Transition relation.

δ_CivOS : S_energy × I_resource × P_user → S_energy s_{t+1} = δ_CivOS(s_t, i_t, p_t)

Mode-boundary form. Mode transitions compare state components against protected policy parameters — for example a critical power boundary of the form b_t < π_critical, where the value of π_critical remains protected. No exact threshold is published.

Energy budget abstraction.

ΔE/Δt = P_sensor + P_audio + P_communication + P_compute + P_storage + P_display + P_overhead

The terms are per-subsystem power-draw classes, not universal constants; their operating values are device- and policy-dependent and remain protected.

Assumptions. A single device's resource state is observable to its own runtime; platform-execution state may change outside CivOS's control.

Public meaning and invariant. CivOS must not advertise capability that the current resource state cannot physically and operationally support.

Protected boundary. Battery-percentage thresholds, comparator values, thermal thresholds, exact sample rates, duty cycles, scheduler intervals, transport-selection rules, register mappings, and hardware power budgets are not disclosed.

Non-claim: this contract describes governing form. It is not a measurement of any real device's battery performance, and implementation conformance requires separate verification.

Seven operating modes

NormalConserveCriticalEmergency BurstLocal-PreserveRecoveryUnavailable
What each mode means and what the user sees
Normal
Nominal power and thermal state; configured sensing and compute; normal interface; transport where available and permitted. Does not imply cloud dependence.
Conserve
Resource pressure or low-risk idle state: batch sensors, reduce nonessential scanning, widen compute intervals, defer nonessential work — while preserving safety-critical sentinel capability.
Critical
Severe energy or thermal constraint: essential sensing and local policy only; nonessential display and transfer suppressed; the user must see the reduced capability.
Emergency Burst
Verified incident or explicit user action: a time-bounded increase in sensing, compute or communication effort, subject to energy and thermal limits. Cannot run indefinitely; must transition back to a bounded mode.
Local-Preserve
Transport unavailable or release denied: state is sealed and retained locally, the preservation state is displayed, and delivery is never implied.
Recovery
Resources return after constrained operation: reassess integrity, reassess policy, restore functions incrementally — no blind jump to full operation.
Unavailable
Required capability absent, runtime suspended or terminated, or integrity cannot be established: explicit unavailability is displayed where possible, and already-sealed state is preserved where possible.

Public transport abstraction

Public transport states: Available · Constrained · Intermittent · Partitioned · Store-and-forward · Local-only · Unavailable. The page explains what each state means, which capabilities remain, what is preserved locally, what the user sees, and whether delivery is confirmed. CivOS exposes transport capability and delivery state. It does not publicly expose the protected physical transport-selection implementation. No radio, medium, routing, hopping, topology, relay, standard, frequency, timing, or countermeasure detail appears on this page.

Public optimization policy classes
Sensor policy
Mode-dependent sensor profile; OS-supported batching where available; quality monitoring; safety-critical sentinel preservation. No exact public sample schedule.
Audio-feature policy
Feature-only by default; no default raw-audio retention; event/session-based activation; low-power sentinel mode where applicable. Exact features and thresholds protected. Ambient or local safety feature extraction is not the Tactical Audio Bridge. TAB is a separately requested and authorized live communication session inside BFB.
Communication policy
Filtered and event-driven operations; batched callbacks where supported; no guarantee of continuous availability; no public transport-selection logic.
Compute policy
Event-driven work; precomputed constants; buffer reuse; model gating; quantization only after accuracy validation. Exact model topology protected.
Storage policy
Encrypted local capsules; append-only event commitments; batched writes; bounded retention. Storage layout and key slots protected.
Display policy
Reduced animation and refresh under constraint; essential status preserved; user denial, disconnect and revoke controls preserved.

Safety corrections

Stationarity alone must never disable safety sensing or suppress an emergency path. Stationarity can mean sleep, device placement, incapacity, injury, loss of consciousness, or ordinary inactivity. It may influence energy policy only when combined with incident state, sensor-quality state, user policy, device context, and other safety signals. Additionally: low battery contracts capability in an explicit priority order; Emergency Burst is time-bounded; thermal throttling is visible; reduced capability is user-visible; no accuracy-preservation claim is made without comparative validation; and platform termination is treated as possible.

Battery evidence classification

Engineering target profile Engineering target — not measured fleet performance
  • Optimized normal-condition target: approximately 1.0–2.0% per hour
  • Optimized dense-condition target: approximately 2.0–3.5% per hour
  • Derived from engineering battery specifications
  • Requires instrumented multi-device testing before any measured claim
Five-minute emergency simulation Stochastic simulation — not hardware validation
  • 2,000 simulated active nodes over a 300-second crisis window
  • 40% starting-battery floor for the test
  • Average start 70.1% · average end 64.1% · mean simulated discharge 6.0%
  • Lowest simulated final battery 34.0%; no simulated node reached zero under that test floor
  • Internal source artifact — public evidence record pending

Non-claim: this result does not establish real-device runtime, low-battery performance below the test floor, operating-system survivability, thermal behavior, field readiness or fleet-wide battery performance.

Mobile platform boundary

CivOS must detect and honestly expose platform capability rather than promise uninterrupted execution. Mobile operating systems may restrict, suspend, restore or terminate background work depending on permissions, user state, system policy and device conditions. No promise is made of indefinite background scanning, continuous background audio, guaranteed background radio behavior, or guaranteed runtime survival on any specific operating system or manufacturer's devices.

Evidence: Simulation-Supported / engineering targetsOperational: Engineering Specification with partial public interface implementation
PHYSICAL ADMISSIBILITY · Admissibility Authority

Threat-Adaptive Safety Response Orchestrator (TSARO)

The deterministic physics and admissibility authority. Core question: is this state or proposed action physically admissible under current uncertainty?

Admissibility AuthorityEngineering SpecificationTransient state only, not retained
Hard boundaryMay not own identity, grant access, release data, optimize athletic performance, rank people, predict opponents, diagnose, replace responders, establish public evidence, or silently expand its own safety boundaries.
Human endpointTSARO's state is not a standalone app — it surfaces inline inside SOS, SSI, and WX-Ag interfaces. See cross-cutting status presentation.
Strongest non-claimNot "unbreakable," not a guarantee of physical safety, not a certified safety system. It contracts safe action under uncertainty — it does not eliminate uncertainty.

Required states

Admissible — inside the safe envelope Held — validation incomplete Degraded — usable only in reduced form Quarantined — isolated due to contradiction Blocked — not permitted Fail-closed — contracts to the safest behavior Silent — insufficient certainty for any claim
Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
The authority that contracts safe action under uncertainty: it checks whether the current or proposed next state stays inside a defined safe set, and refuses when it can't confirm that.
Why it exists
A statistical model, external feed, institutional request, or interface can produce a plausible output that still violates physical, safety, confidence, or integrity requirements.
Real-world failure it prevents
Any model — however capable — taking or recommending an action that cannot be shown to keep the system in a safe state.
Authority it owns
Safe-set evaluation, physical plausibility, boundary enforcement, uncertainty contraction, admissibility classification, fail-closed behavior, silence.
Inputs
Current state estimate, safe-set constraints, W-X truth admissibility, domain-model candidate outputs, device integrity, sensor agreement, model envelope.
Governing mechanism
Evaluate whether the current/proposed state stays inside the safe set; if not, compute the minimal feasible correction, or fail closed if none exists.
Outputs
An admit / contract / fail-closed decision, an admissibility class, and a confidence boundary. No hidden thresholds are disclosed publicly.
Human recipient / device
TSARO's state is not a standalone app — it surfaces inline inside SOS, SSI, and WX-Ag interfaces. See cross-cutting status presentation.
What it may do
Admit, contract, hold, degrade, quarantine, block, fail-closed, or stay silent.
What it may not do
Own identity, grant access, release data, optimize athletic performance, rank people, predict opponents, diagnose, replace responders, establish public evidence, or silently expand its own safety boundaries.
Dependencies
Sovereign Root's constitutional refusal principle; requires valid CivOS substrate and W-X truth to evaluate against.
Components it constrains
SOS, SSI, WX-Ag, and CivOS all consult TSARO before acting on their own outputs; where a release depends on physical or safety admissibility, NICOLE Protocol cannot authorize that release unless TSARO has admitted the relevant state. TSARO never releases anything itself.
Components that constrain it
Sovereign Root's refusal doctrine bounds TSARO's posture; W-X truth quality bounds what TSARO can evaluate against.
Normal operation
Continuous admissibility evaluation against the current safe set, admitting or minimally contracting proposed states.
Degraded operation
Rising uncertainty narrows (never expands) the safe set; more uncertainty can only preserve or contract admissibility.
Adversarial / conflicting-input behavior
Contradictory inputs (e.g. a route reported available while environmental/obstruction state conflicts) hold or degrade the proposed state rather than admitting it optimistically.
Public-safe implementation pattern
Safe-set projection: u*_t = argmin‖u−u_requested‖ subject to f(x_t,u) ∈ C_t. Uncertainty contraction: ω₂ ≥ ω₁ ⇒ C_t(ω₂) ⊆ C_t(ω₁) — more uncertainty can shrink the safe set, never grow it.
Protected implementation boundary
Exact coercion triggers, motion thresholds, threat thresholds, hidden timing rules, acoustic-buffer triggers, deception logic, and predictive weights are never disclosed. Coercion-resistance and incapacitation-response concepts from confidential source specifications remain Provisional R&D.
Current implementation
Safe-set logic demonstrated as a public-safe math block on proof-library.html.
Maturity / evidence state
Engineering Specification. Two reviewed source documents describe a much larger TSARO — one a hardware-countermeasures platform, one a predictive-wearable ecosystem — neither matches what is live; both are documented as unimplemented conflicts, not imported as current capability.
Public non-claims
Not "unbreakable," not a guarantee of physical safety, not a certified safety system. It contracts safe action under uncertainty — it does not eliminate uncertainty.
Open related simulation
sos-civos-proof-theater.html.
Open related evidence
Safe-set projection block on proof-library.html.
Canonical fragment ID
#tsaro — preserved; 17 other pages link here.
Real-world scenario analogue
SOS route conflict
Situation
A route appears available, but environmental and obstruction state conflict.
Human actor
Civilian user and responder.
Device / interface
User's phone; responder's BFB tablet.
What is observed
A candidate route and conflicting obstruction/environmental signals.
What LAKANA computes
Whether the route stays inside the safe set given the conflict.
Which authority evaluates it
TSARO.
What is shown
A held or degraded route state, not a confident "clear" label.
What is withheld
Any claim that delivery or the route is fully successful.
What action LAKANA takes
Holds or degrades the route, permits local preservation, requires new support before release.
What remains a human decision
Responder tactical routing decisions.
Failure behavior
Fail-closed to the conservative route state.
Current evidence level
Public Simulation.
What would require field validation
Real obstruction-sensor accuracy in field conditions.
Real-world scenario analogue
SSI structural-burden approach
Situation
Structural burden approaches the modeled envelope during a training session.
Human actor
Athlete or worker.
Device / interface
Athlete's phone/tablet.
What is observed
Rising structural-pressure proxy from SSI.
What LAKANA computes
Whether the proxy state stays inside the safe envelope.
Which authority evaluates it
TSARO.
What is shown
A contracted, bounded warning state to the athlete.
What is withheld
Any medical clearance or disqualification determination.
What action LAKANA takes
Contracts the permissible state and issues a bounded warning.
What remains a human decision
Medical clearance and return-to-play decisions stay with licensed professionals.
Failure behavior
Withholds a confident estimate rather than guessing.
Current evidence level
Public Simulation.
What would require field validation
Clinical correlation with actual injury outcomes.
Formal public admissibility contract — state spaces, safe set, projection, dictionary, boundary

State and input spaces.

x_t ∈ X u_t ∈ U ω_t ∈ Ω

Variable dictionary. x_t — current domain state; u_t — proposed action or output; ω_t — uncertainty state.

Safe set.

C_t(ω_t) = { x ∈ X : g_i(x, ω_t) ≤ 0, i = 1, …, m }

Public projection.

u*_t = argmin_{u ∈ U} ‖ u − u_requested ‖_Q subject to f(x_t, u, ω_t) ∈ C_t(ω_t)

Uncertainty non-expansion.

ω₂ ⪰ ω₁ ⇒ C_t(ω₂) ⊆ C_t(ω₁)

Assumptions. The safe set is defined over the declared state space with the declared constraint family; the uncertainty ordering ⪰ is the declared partial order.

Public meaning. Under the declared assumptions, greater uncertainty may preserve or contract the admissible set. It must not enlarge it.

Protected boundary. The weighting matrix Q, constraint coefficients, internal thresholds, risk maps, trust distributions, internal state-estimation weights, and actuator bindings are not disclosed.

Non-claim: this is a governing mathematical form, not a claim that every implementation is formally verified against it. Implementation conformance requires separate verification.

CRYPTOGRAPHIC GOVERNANCE · Custody Authority · Operational governance rail

NICOLE Protocol

Non-Interactive Cryptographic Oversight & Ledger Enforcement

Decides who may access, hold, or receive released data, under what role, scope, consent, and time window — and logs every decision, granted or denied. NICOLE Protocol governs operational access and release. SSES governs public evidence and claims — separate concerns with separate scopes, not one combined rail.

Custody AuthorityPublic Simulation / ReceiptCustody / Lease Metadata, Audit Ledger
Hard boundaryMay not determine physical truth, calculate structural burden, validate weather, calculate crop state, prove model accuracy, guarantee legal admissibility, or make an authorized action scientifically correct.
Human endpointNICOLE Protocol's state surfaces inline in every domain interface as authorized / scope-limited / pending / denied / revoked / expired / preserved / audit-recorded. See delivery.
Strongest non-claimNot a certified privacy or regulatory-compliance product by itself; the audit ledger is a design pattern, not a formal legal attestation; does not guarantee legal admissibility in every jurisdiction.

What each word means

Non-Interactive
The enforcement model is designed so boundaries do not depend entirely on a human administrator manually approving every request.
Cryptographic
Identity, integrity, scope, leases, releases, and custody may be cryptographically bound where implemented.
Oversight
Permitted, denied, revoked, expired, and overridden actions remain visible.
Ledger
Relevant access and decision events are recorded.
Enforcement
Rules deny, terminate, expire, or revoke access instead of merely describing policy.
Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
Decision causality, bounded release, evidence lineage, role-scope, and custody discipline, expressed as one release-validity check applied everywhere.
Why it exists
A system may be physically correct and still violate a person's rights if the wrong party receives an output, access lasts too long, consent is unclear, revocation is ignored, or an override is hidden.
Real-world failure it prevents
Any single role having standing, unscoped access to sensitive state, and any release happening without an accountable, revocable record.
Authority it owns
Identity, role, purpose, scope, consent, lease, duration, release, denial, revocation, expiration, custody, audit, decision causality.
Inputs
Requester role, requested scope, active consent/lease state, epoch/expiry, revocation flags.
Governing mechanism
role ∧ scope ∧ consent/lease ∧ epoch ∧ no revocation ∧ audit — the full release-validity conjunction, for every protected, personal, custody-sensitive, or role-scoped operational release.
Outputs
A grant / deny / expire decision, plus an immutable audit-ledger entry either way.
Human recipient / device
NICOLE Protocol's state surfaces inline in every domain interface as authorized / scope-limited / pending / denied / revoked / expired / preserved / audit-recorded. See delivery.
What it may do
Grant, deny, scope-limit, revoke, or expire any access or release; write an audit-ledger entry for every decision.
What it may not do
Determine physical truth, calculate structural burden, validate weather, calculate crop state, prove model accuracy, guarantee legal admissibility, or make an authorized action scientifically correct.
Dependencies
Sovereign Root — consent is the constitutional principle NICOLE Protocol enforces mechanically.
Components it constrains
Every component that discloses anything: SOS, BFB (including its TAB feature), SSI, and WX-Ag all pass through NICOLE Protocol before release. SSES separately checks with it only for what may be published.
Components that constrain it
Where a release depends on physical or safety admissibility, NICOLE Protocol cannot authorize that release unless TSARO has admitted the relevant state. TSARO never releases anything itself. TSARO is not required for consent revocation, lease expiration, scope denial, public paper access, nonphysical custody events, review-session closure, or public evidence decisions that contain no physical-admissibility question.
Normal operation
Every request evaluated against the full conjunction; grants and denials both logged.
Degraded operation
Any missing conjunct denies the request silently and by default — degradation never expands access.
Adversarial / conflicting-input behavior
A request for scope beyond an active lease, or after revocation, is denied and the denial itself is audit-visible.
Public-safe implementation pattern
Access validity: AccessValid_k = 1{r_k∈R} · 1{s_k⊆S(r_k)} · 1{q_k∈Q_active} · 1{sig_k=1} · 1{lease_k=1}. Ledger abstraction: ℓ_k = H(ℓ_{k−1} ‖ r_k ‖ d_k ‖ s_k ‖ τ_k ‖ c_k ‖ q_k). r=role, s=scope, q=consent/lease state, sig=signature validity, τ=time, c=custody transition, H=hash.
Protected implementation boundary
Real key material, salts, internal cryptographic contexts, and production secrets are never disclosed — the formulas above describe governing form, not exact production parameters.
Current implementation
Ledger entries visible in per-model "NICOLE ledger" panels and the receipt system on sos-civos-proof-theater.html.
Maturity / evidence state
Public Simulation / Receipt for the ledger pattern; Architecture Doctrine for the full cryptographic protocol; External Security Validation Required before any certification claim. One reviewed source specification pairs NICOLE with a much larger predictive-biometric sentinel surface — this chapter keeps NICOLE Protocol strictly to its production custody/audit role and documents that source's broader claims as unimplemented.
Public non-claims
Not a certified privacy or regulatory-compliance product by itself; the audit ledger is a design pattern, not a formal legal attestation; does not guarantee legal admissibility in every jurisdiction.
Open related simulation
Per-model NICOLE ledger panels (for example the Farmer model's ledger).
Open related evidence
Receipt system on sos-civos-proof-theater.html.
Canonical fragment ID
#nicole — preserved; 17 other pages link here.
Release validity: role ∧ scope ∧ consent/lease ∧ epoch ∧ no revocation ∧ audit

Ledgers

Immutable Access Ledger
  • Requester, role, scope
  • Device or credential, time
  • Grant, denial, expiration, revocation
Decision Causality Ledger
  • Warning, requested action, override
  • Responsible role, acknowledgment
  • Time, result
Evidence Custody Record
  • Artifact identity, integrity reference
  • Custody transition
  • Release / preservation / expiration / destruction state

Role-specific scenarios

Real-world scenario analogue
Coach requests raw athlete telemetry
Situation
A coach requests raw individual telemetry outside their authorized scope.
Human actor
Coach; athlete (subject).
Device / interface
Coach's tablet or desktop.
What is observed
An access request naming a scope broader than the coach role's authorization.
What LAKANA computes
Whether the requested scope is a subset of the coach's authorized scope.
Which authority evaluates it
NICOLE Protocol.
What is shown
Denial, with a visible reason.
What is withheld
Raw telemetry; the coach receives only the bounded authorized summary.
What action LAKANA takes
Denies and logs the denial; athlete may be notified where appropriate.
What remains a human decision
Institutional policy about what scope a coach role is granted in the first place.
Failure behavior
Deny by default.
Current evidence level
Public Simulation / Receipt.
What would require field validation
Institutional-scale role-policy testing.

BFB versus TAB under NICOLE Protocol: a responder may hold active BFB incident access while TAB remains unavailable, not requested, pending, denied, active, disconnected, revoked, or expired — each state tracked and audit-visible independently.

Threshold custody and key lifecycle

NICOLE Protocol governs who may request, receive, retain, revoke, expire, review or release protected state. It owns custody and permission boundaries; it does not determine physical truth, diagnose a person, validate a route or establish a public scientific claim. NICOLE Protocol governs protected, personal, custody-sensitive and role-scoped access, release, retention, revocation and audit — it does not imply that every public environmental observation requires personal consent governance. Where a release depends on physical or safety admissibility, NICOLE Protocol cannot authorize the release unless TSARO has admitted the relevant state; not every NICOLE Protocol action requires TSARO.

Refusal-state contract
PendingAuthorizedScope-limitedDeniedRevokedExpiredIntegrity-failedLocally preservedReview-session activeReview-session closed
Public permit relation — formal contract and dictionary
Permit(q,t) = 1{role valid} · 1{scope allowed} · 1{purpose allowed} · 1{lease active} · 1{not revoked} · 1{integrity valid} · 1{required approvals present}

Variable dictionary. A request q carries public field classes only: role class, purpose class, scope class, time boundary, integrity state, approval state, revocation state. Actual role maps and policy tables are not published.

Assumptions. Requests are evaluated against a current, versioned policy state; a missing or ambiguous conjunct evaluates to zero.

Public meaning. Every conjunct must independently hold; degradation or ambiguity narrows access, never widens it.

Protected boundary. Real key material, salts, derivation contexts, custodian maps, quorum values, and production secrets are never disclosed.

Non-claim: the relation describes governing form. Implementation conformance requires separate verification; a symbolic relation does not prove every implementation satisfies it.

Evidence capsule — public interface contract
Evidence Capsule — public field classes
├── capsule version
├── encrypted content
├── content commitment
├── source class
├── purpose class
├── policy identifier class
├── lease start and expiry
├── revocation state
├── custody-event commitment
└── integrity/signature state

This is a public architecture contract, not the production wire schema. No actual identifiers, signing contexts, storage paths, recipient maps, key references, internal object names, or serialization formats appear here.

Corrected threshold-custody model — two separated maturity tracks
Near-term engineering profile Engineering Specification / staged implementation
  • Per-capsule symmetric encryption key
  • Standardized endpoint cryptography
  • Hardware-backed keys where available
  • Independent signed custodian approvals
  • Application-level quorum
  • Re-encrypted or rendered authorized view; reusable plaintext export denied by default
  • Append-only custody events recording grant, denial, expiry and revocation
Threshold research profile Research track — external analysis required
(PK, sk₁, …, sk_n) ← DKG(policy) μ_j ← PartialOp(sk_j, request context) output ← Combine({ μ_j : j ∈ A })

The target design distributes trust so no central party is intended to hold the full private capability. Security and correctness depend on the selected threshold scheme, adversary model, authenticated channels, share lifecycle, implementation and external analysis. No fixed quorum values, share topology, real polynomial, field parameters, custodian identities, or scheme internals are published.

Standardized primitive boundary

Three classes are kept publicly distinct: standardized primitives (ML-KEM, ML-DSA); the LAKANA integration class (capsule encryption, device identity, signed custody events, release workflow); and the research class (threshold post-quantum operation, fully homomorphic policy evaluation, independent custodian hardware, externally verified secure erasure).

Non-claim: standardized cryptographic primitives do not automatically validate LAKANA's integration, custody model, threshold architecture or hardware implementation.

Domain separation — public abstraction
context_id = H( policy class ‖ incident nonce ‖ capsule version ‖ purpose class ) K_capsule = KDF( K_parent, context_id, random salt )

Public meaning. Separate incidents, separate purposes, and separate policy domains derive separate key material, reducing accidental cross-use.

Protected boundary. Actual context encoding, actual salts, KDF labels, root-key layout, key slots, and device secrets are not disclosed.

Pumpkin key-lifecycle profile — nested inside NICOLE Protocol

The Pumpkin key-lifecycle profile is a NICOLE Protocol key-lifecycle design in which time-bounded access may end through expiration, revocation and destruction or invalidation of derived key material rather than reliance on file deletion alone. It is not a separate top-level system.

K_e = KDF( K_parent, e, policy context, ν_e ) t ≥ τ_e ∨ revoked(e) = 1 ⇒ Permit(e,t) = 0

Dictionary. e — abstract epoch; ν_e — public abstraction of an epoch-specific nonce; τ_e — expiration boundary. On expiry or revocation the derived access-key reference is invalidated, future access requires a new authorized path, and an audit event is appended.

Non-claim: this public relation does not disclose derivation contexts, root-key storage, hardware slots, zeroization routines or production key-management implementation. It does not by itself prove physical erasure or absolute unrecoverability across every device, compiler, memory subsystem, crash path, swap path or forensic condition.

Zeroization profile — public layers and caveats
Application memory
Minimize lifetime, avoid unnecessary immutable copies, explicit buffer lifecycle, crash-path cleanup. Boundary: language runtimes and compilers may retain copies.
Hardware-backed operations
Use non-exportable key operations where supported. Boundary: assurance varies by platform.
Registers and enclave memory
Tested implementation-specific cleanup; release execution lock only after the cleanup profile completes. Boundary: exact instructions and register maps protected.
Persistent storage
Encrypted at rest; destroy or invalidate key references; tombstone policy state; controlled compaction. Boundary: flash wear leveling prevents simplistic physical-erasure claims.
Logging
Never log keys, raw plaintext, salts, sensitive contexts, or full protected payloads.
Integrity and custody commitments — versioned Merkle commitment tree
leaf_i = H( capsule commitment_i ‖ metadata commitment_i ‖ version_i ) root_k = MerkleRoot( leaf₁, …, leaf_n ) ledger_k = H( ledger_{k−1} ‖ root_k ‖ decision_k ‖ scope_k ‖ expiry_k ) signature_k = Sign( authority key, ledger_k )

Public meaning. Capsule and metadata commitments roll up into a versioned Merkle commitment tree whose roots chain into the append-only custody ledger; each ledger entry is signed. No salts, keys, device IDs, derivation labels, key slots, hardware addresses, or recipient maps appear.

Controlled review flow

  1. Requester submits role, purpose, scope, time boundary and capsule class.
  2. NICOLE Protocol verifies identity, policy, user authorization or valid pre-authorized doctrine, revocation and applicable conditions.
  3. Independent custodians evaluate the same versioned request context.
  4. Required approvals or partial operations are collected.
  5. An isolated, time-bounded review session receives only the authorized view.
  6. The view is rendered in place or re-encrypted to the approved endpoint.
  7. Reusable plaintext export is denied by default.
  8. Session, expiry, revocation, custody transition and cleanup state are recorded.

Public architecture flow — not a production cryptographic proof.

Sovereign Home Anchor profile — optional nested R&D card

Provisional / R&D An optional user-owned local node profile for encrypted local preservation, policy continuity, and later relay when an authorized transport becomes available. Public properties: user-owned, local, encrypted capsules, append-only commitments, revocable enrollment, rotating session relationship, island mode, local preservation. No claim is made of continuous availability, guaranteed responder egress, guaranteed uptime, or resistance to any radio-interference condition.

Concrete scope examples — what each role may and may not do
SOS / BFB responder
May view the bounded incident workspace for the active incident and lease. May not view unrelated history, receive permanent device access, or start TAB automatically.
TAB
Responder may request audio. May not begin audio before separate authorization, or continue after revoke or expiry.
SSI coach
May view the bounded team or workload envelope for the authorized period. May not view unrestricted individual recovery history or unrelated medical information.
SSI medical/training lease
Authorized staff may view relevant derived state during a valid lease. May not receive permanent entitlement or convert access into medical authority.
WX-Ag external sharing
A recipient may receive a bounded field manifest under the owner's scope. May not receive unrelated farm history or treat the manifest as a yield guarantee or insurance determination.
Evidence: Architecture and standards-aligned researchOperational: application-level quorum — staged implementation; threshold custody — research profile
PUBLIC EVIDENCE GOVERNANCE · Public Evidence Adjudication Perimeter

Sovereign Structural Evidence Stack (SSES)

Eight post-run evidence-governance layers that determine what a completed simulation artifact is allowed to support publicly — applied after the result already exists, never before. The domain model creates the result. SSES adjudicates what the completed public-safe artifact is allowed to support publicly. NICOLE Protocol governs operational access and release; SSES governs public evidence and claims — separate concerns with separate scopes, not one combined rail.

Public Evidence Adjudication PerimeterPublic Simulation / staged evidence recordsPublic Proof-Bounded, Aggregate Statistical
Hard boundaryMay not change the underlying simulation result, or grant operational access to it — that is NICOLE Protocol's job.
Human endpointPublic visitors on the Proof Library, Evidence, and Papers pages — not a role-specific operational interface.
Strongest non-claimNot a peer-review process, not a regulatory certification, not a guarantee that no unpublished internals exist, and not a claim of complete claim-to-artifact traceability across every result on the site.
Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
The eight-layer, post-run evidence-governance system that decides what a completed simulation artifact is allowed to support publicly — separate from whether the underlying result is true, and separate from NICOLE Protocol's operational custody of the result itself.
Why it exists
A simulation can be technically correct and still get oversold in public language if nothing separately governs source linkage, scope boundaries, contradiction, and non-extractive release.
Real-world failure it prevents
Public copy drifting ahead of what has actually been tested, computed, or validated.
Authority it owns
Whether a result may be published, with which evidence-governance layer values, maturity label, and non-claims attached.
Inputs
Completed simulation/model output for a branch — SSI, SOS/CivOS, or W-X/WX-Ag — its source linkage, and its declared claim boundary.
Governing mechanism
Apply all eight layers — MEBVB, SPCS, RET-BURD, MCAC, SAFE-N, ELCI, SCLG, TAF — separately per branch, then gate publication on the combined result.
Outputs
Public-safe artifacts carrying evidence-class, maturity label, and non-claims: manifests, receipts, papers, and figures.
Human recipient / device
Public visitors on the Proof Library, Evidence, and Papers pages — not a role-specific operational interface.
What it may do
Publish, withhold, or attach a required non-claim to any branch's result.
What it may not do
Change the underlying simulation result, or grant operational access to it — that is NICOLE Protocol's job.
Dependencies
Sovereign Root (constitutional claim-discipline principle); NICOLE Protocol (SSES may only publish what NICOLE has already cleared for aggregate/public release).
Components it constrains
Every public-facing page that shows a number, chart, or claim from SSI, SOS/CivOS, or W-X/WX-Ag.
Components that constrain it
NICOLE Protocol clears release scope before SSES ever sees material; Sovereign Root sets the claim-discipline doctrine SSES enforces.
Normal operation
A completed branch result passes through all eight layers; a publishable artifact carries every layer's value and non-claim.
Degraded operation
A layer that cannot yet be computed for a branch is marked "architecture schematic" rather than silently omitted or estimated.
Adversarial / conflicting-input behavior
A result whose source-linkage or contradiction checks fail is withheld from publication, not published with a caveat buried at the bottom.
Public-safe implementation pattern
Eight per-layer formulas, one per section below; combined they gate whether and how a result may be shown publicly.
Protected implementation boundary
Internal weighting between layers, and any layer's full computation pipeline beyond its stated public-safe formula, is not disclosed.
Current implementation
Production-Deployed Interface as a publishing discipline and as pages — proof-library.html, evidence.html, and claim-matrix.html are live today; individual layer values below are computed per branch as shown, not uniformly complete across every result on the site.
Maturity / evidence state
Production-Deployed Interface (publishing discipline) / Public Simulation (branch values — mixed data-backed and architecture-schematic per layer, marked individually below).
Public non-claims
Not a peer-review process, not a regulatory certification, not a guarantee that no unpublished internals exist, and not a claim of complete claim-to-artifact traceability across every result on the site.
Canonical fragment ID
#sses — preserved from the prior rebuild.

Each layer below applies separately to each branch that has reached simulation completion — Sovereign Structural Intelligence (SSI), Safety Operating System / CivilizationOS (SOS/CivOS), and Weather Exchange / WX-Ag (W-X/WX-Ag) — because the branches do not share evidence, only the governance method. Every branch value carries an evidence-type badge: data-backed means the value was computed from an actual completed simulation run; architecture schematic means the layer's mechanism is shown for that branch without a full data run behind it yet.

NICOLE Protocol → determines whether an artifact may leave protected custody
SSES           → determines what that released artifact may support publicly
Proof Library  → stores and exposes the bounded evidence record

Claim posture: the branch values below are simulation-stage evidence-governance results under each branch's declared model. They support simulation-stage architecture and pathway statements only; they do not support field validation, clinical efficacy, deployment certification, or outcome claims. Where a value is not yet backed by a complete public artifact: Public evidence record incomplete — Proof Library rebuild pending.

Layer 1 — MEBVB Monotone Empirical Bernstein Variance Bound

Computes a monotone empirical-Bernstein variance-bound interval around a branch's output distribution — how much a result could plausibly vary given the simulation's own declared bound and confidence level, not a real-world margin of error.

ε = [⅔R·ln(2/α) + √((⅔R·ln(2/α))² + 8Bs²ln(2/α))] / 2B Interval: [μ̄−ε, μ̄+ε]
data-backedSSI — whole frame

B=390 · interval [953,444.21, 1,205,922.71]

data-backedSSI — female stack

B=180 · interval [2,280,391.93, 3,111,841.08]

data-backedSOS/CivOS

mean 0.011308, half-width 0.001215 · interval [0.010093, 0.012523]

data-backedW-X/WX-Ag

B=16, mean 1.000 · interval [1.000, 1.000]

Non-claim: this interval describes statistical spread inside a declared simulation model — it is not a real-world confidence interval, a clinical margin, or a field-validated error bar.

Layer 2 — SPCS Source-Path / Structural Persistence Concordance

Scores whether a structural result persists coherently along its source path: each source's contribution is weighted, and the concordance score is discounted whenever sources actually contradict each other — so a confident-looking aggregate cannot hide source-path disagreement underneath it.

SPCS = (Σ w_j s_j / Σ w_j)(1 − ContradictionRate)
architecture schematicSSI

Mechanism shown; branch-level score not yet run to completion.

data-backedSOS/CivOS

score 1.000, contradictions 0

data-backedW-X/WX-Ag

score 1.000, contradictions 0, heuristic-threshold disclosures 7

Non-claim: a high SPCS score means the sources that were checked agreed with each other under the declared model — it does not mean every possible source was checked.

Layer 3 — RET-BURD Retained-Time / Burden Reallocation Surface

A reallocation surface crossing retained time against burden, classifying each eligible case as favorable, a managed trade-off, or adverse/ambiguous — a structural pathway view, not an outcome guarantee.

data-backedSSI — whole frame

eligible 390 · favorable-lower-burden 360 · favorable-higher-burden trade-off 30 · adverse/ambiguous 0

data-backedSSI — female stack

eligible 180 · dominant favorable 162 · managed-burden trade-off 18 · adverse 0

data-backedSOS/CivOS

eligible rows 5 · favorable-with-delivery-support 5

data-backedW-X/WX-Ag

eligible rows 15 · favorable-timing, no anoxia increase 15

Non-claim: a favorable quadrant placement describes the simulated structural pathway under the declared model — it is not a burden-reduction outcome measured in the field.

Layer 4 — MCAC Model-Family Concordance and Adjudication Cube

A concordance-and-adjudication structure over model families, presented publicly as a two-dimensional matrix — explicitly not three-dimensional — scoring each family's availability and completeness as a readiness value. Packaging pending does not mean not computed.

data-backedSSI

19 model-family rows

data-backedSOS/CivOS

17 rows, mean readiness ≈0.926

data-backedW-X/WX-Ag

16 rows, mean readiness ≈0.953

Non-claim: readiness describes whether a model family's evidence has been computed and structured for review — it does not describe deployment readiness or field maturity.

Layer 5 — SAFE-N Source-and-Aggregate Fidelity Evidence, Normalized

Starts from a base source-and-aggregate fidelity score and subtracts declared penalties — exposure, unverified heuristic thresholds — to produce a normalized score that does not hide known weaknesses inside a single confident number.

data-backedSSI

adjusted ≈0.7886

data-backedSOS/CivOS

base 1.000, adjusted 0.950

data-backedW-X/WX-Ag

base 1.000, exposure penalty 0.020, heuristic-threshold penalty 0.014, adjusted 0.966

Non-claim: the adjusted score reflects declared, disclosed penalties under the current model — it is not a certified safety rating.

Layer 6 — ELCI Evidence-Lineage Completeness Index

Walks the claim-lineage network behind a public result and scores how completely each claim traces back to a source — a completeness measure, not a truth measure.

data-backedSSI

global mean ≈0.9185

data-backedSOS/CivOS

9 of 9 complete, score 1.000

data-backedW-X/WX-Ag

10 of 10 complete, score 1.000

Non-claim: a complete lineage means every claim traces to a declared source — it does not mean the source itself has been externally validated.

Layer 7 — SCLG Sensitivity-to-Claim Leverage Gate

Gates how much leverage a sensitivity result may exert on a claim: a governing parameter links to the claims that depend on it only where a claim boundary is explicitly linked — so a sensitivity finding cannot silently support a claim it was never scoped to support.

SCLG_{j,c} = ℓ_j · 1{c depends on j} · 1{claim boundary linked}
architecture schematicSSI

Mechanism shown; branch-level linkage graph not yet run to completion.

data-backedSOS/CivOS

dominant parameter "TSARO threshold" · S₁≈0.983 · S_T≈0.993 · status: stable with precision and boundary disclosure

data-backedW-X/WX-Ag

top row: baseline trigger parameter group · metric mean water · status: unverified threshold sweep, not calibration · claim status: stable with disclosure

Non-claim: a linked parameter shows which claims a sensitivity result may support — a threshold sweep is not itself a calibration against real-world data.

Layer 8 — TAF Tail Adjudication Frontier

Adjudicates which tail rows are eligible for attribution at the frontier: a row is eligible only when its event count, its denominator, and their sources all agree and the denominator is nonzero — so a claim can't attribute a tail outcome to a source that never actually reported it.

TAFEligible_r = 1{n_event,r present}·1{n_r present}·1{source(n_event,r)=source(n_r)}·1{n_r>0}
data-backedSSI

eligible 156 · excluded 0

data-backedSOS/CivOS

eligible 4 · excluded 0

data-backedW-X/WX-Ag

eligible 2 · excluded 0

Non-claim: eligibility means the attribution is internally traceable under the declared model — it does not mean the underlying event was externally verified.

Branch portability map — what each branch may and may not claim publicly

SSI

Allowed: Simulation-stage structural pathway and evidence-governance results under the declared model.

Forbidden: Injury prevention, clinical efficacy, demographic validation, field burden reduction.

SOS/CivOS

Allowed: Simulation-stage architecture differentiation evidence.

Forbidden: Emergency-service replacement, rescue guarantee, deployment certification, real-world protected-outcome proof, formal privacy/security certification.

W-X/WX-Ag

Allowed: Simulation-stage source-supported environmental and agronomic pathway evidence.

Forbidden: Yield guarantee, field agronomy validation, operational weather authority, real-world farm-outcome proof, regulatory/advisory authority.

SSES evidence governance: MEBVBSPCSRET-BURDMCACSAFE-NELCISCLGTAF Claim posture: allowed statements are simulation-stage architecture and pathway evidence; stronger field/clinical/deployment statements are prohibited. Where a record is not yet complete: Public evidence record incomplete — Proof Library rebuild pending.
CIVILIAN SAFETY DOMAIN · Coordination Authority

Safety Operating System (SOS)

The Safety Operating System is LAKANA's civilian-side safety domain. It transforms local incident observations into minimized, physically admissible and consent-governed safety state; preserves that state during degraded operation; presents bounded information to the user; and coordinates authorized responder handoff through the Blue Force Bridge when release conditions are satisfied. Not "Sovereign Operating System."

Coordination AuthorityEvidence: Public Simulation / ReceiptOperational: Public interactive simulation, not field deploymentCivilian Distress State
Refusal-state contract — what this design refuses to do
  • Does not claim delivery when transport failed
  • Does not grant unrestricted responder access
  • Does not open TAB automatically
Hard boundaryMay not decide whether an action is physically safe (TSARO), decide whether data may be released (NICOLE Protocol), or open continuous/standing access to a person's raw state.
Human endpointCivilian/protected user at the civilian interface (primary); responder at BFB (optional). Full device-by-device receive-lists in how information reaches the correct person.
Strongest non-claimNot emergency certification, not official dispatch, not a replacement for 911 or professional responders, not a guaranteed rescue.

SOS first presents bounded safety state to the user through the user's own phone, tablet, or supported wearable-linked interface. A responder receives a different, minimized, incident-scoped packet through BFB only when the applicable TSARO and NICOLE Protocol conditions are satisfied.

Operating path

Local observation                          (required)
→ CivOS capability state                   (required)
→ incident-state minimization              (required)
→ relevant W-X context                     (where applicable)
→ TSARO admissibility                      (required before any release)
→ NICOLE Protocol release evaluation       (required before any release)
┌───────────────────────────────────────────────────────┐
│ First-party user presentation (required)               │
│ User's own phone, tablet, or supported wearable         │
└───────────────────────────────────────────────────────┘
→ optional responder branch:
    → Blue Force Bridge responder workspace  (optional)
    → optional TAB request inside BFB        (optional, separately authorized)
→ audit, expiry and closure                (required)
Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
The full civilian-side safety domain: incident-state interpretation, local preservation, user-facing safety information, state minimization, TSARO-admissibility interaction, NICOLE Protocol-governed release, optional responder handoff through BFB (with nested TAB), and audit and closure — not merely packet delivery or responder routing.
Why it exists
"Safety monitoring" can silently become continuous surveillance unless one authority's only job is bounded routing to a human, never standing access.
Real-world failure it prevents
Two opposite failures at once: staying silent when someone needs bounded help, and opening unrestricted access in the name of "safety."
Authority it owns
Which minimized safety state reaches the user's own device (the primary path), and — separately and optionally — which minimized packet, if any, reaches a responder through BFB.
Inputs
Local distress/incident state, TSARO's admissibility result, NICOLE Protocol's release decision, CivOS transport/availability state.
Governing mechanism
Detect candidate incident state → minimize to only the necessary fields → require TSARO admissibility → require NICOLE Protocol release clearance → route through CivOS's available transport → deliver to the correct human interface → audit regardless of outcome.
Outputs
Bounded safety-state presentation delivered to the user's own device — the primary output. Separately and optionally, a minimized responder packet delivered into the BFB workspace when release conditions are met, inside which BFB's own TAB feature may open a consent-gated audio session; nothing delivered when any required gate fails.
Human recipient / device
Civilian/protected user at the civilian interface; responder at BFB. Full device-by-device receive-lists in how information reaches the correct person.
What it may do
Minimize, route, deliver to an authorized human interface, withhold, and log every attempt whether it succeeds or not.
What it may not do
Decide whether an action is physically safe (TSARO), decide whether data may be released (NICOLE Protocol), or open continuous/standing access to a person's raw state.
Dependencies
CivOS transport/availability; TSARO admissibility; NICOLE Protocol release clearance.
Components it constrains
BFB, and BFB's nested TAB feature, which can only display or open what SOS has already routed and cleared.
Components that constrain it
TSARO (nothing moves without admissibility); NICOLE Protocol (nothing is released without clearance); CivOS (no transport, no delivery).
Normal operation
Incident detected → minimized → cleared → delivered → logged, typically within the same interaction.
Degraded operation
CivOS local-only / store-and-forward mode delays delivery and shows an honest "preserving, not yet delivered" state rather than a false "sent" state.
Adversarial / conflicting-input behavior
Conflicting or ambiguous distress signals hold at "insufficient to act" — SOS never escalates to an assumed emergency without TSARO and NICOLE Protocol clearance.
Public-safe implementation pattern
SOS path: local state → minimize → TSARO → NICOLE Protocol → user's own device (primary); optional branch → BFB (optional TAB audio inside BFB) → audit. Exact minimization rules and trigger thresholds are not disclosed.
Protected implementation boundary
Exact minimization rules, trigger thresholds, and responder-matching logic remain undisclosed.
Current implementation
Public Simulation / Receipt on sos-civos-proof-theater.html; partly Academic Capstone Reviewed through the professor capstone review track.
Maturity / evidence state
Public Simulation / Receipt.
Public non-claims
Not emergency certification, not official dispatch, not a replacement for 911 or professional responders, not a guaranteed rescue.
Open related simulation
sos-civos-proof-theater.html.
Open related evidence
sos-capstone-review.html.
Canonical fragment ID
#sos — preserved.
SOS path: local state → minimize → TSARO → NICOLE Protocol → user's own device (primary) optional branch → BFB (optional TAB audio inside BFB) → audit

Civilian interface

The civilian or protected user's own device — phone, tablet, or a supported wearable interface — is the primary SOS surface. It shows incident status, local preservation state, route or muster information, responder handoff status, and any TAB request with accept/deny controls. The civilian does not operate BFB as a personal view; full per-role receive-lists are in how information reaches the correct person.

Muster

Muster is the bounded rally-point function: CivOS transport state and TSARO route-admissibility together determine a small set of safe, reachable gathering points during an incident. Muster points reach the civilian interface as location and status only — not a live feed of who else is present.

Routes

Route candidates are generated from CivOS transport/availability state and must clear TSARO admissibility before SOS will offer or relay them; a route that looks geometrically clear but conflicts with environmental or obstruction state is held or degraded rather than confidently offered (see the TSARO chapter's route-conflict scenario).

Accountability

Accountability tracks who has been accounted for during an incident as a small set of states — accounted, unaccounted, in transit, handed off — visible to BFB responders at their authorized scope. It is a coordination state, not a permanent roster or identity database.

Triage

Triage priority is a bounded severity/priority classification handed to responders inside BFB to help sequence attention — never a medical diagnosis, and never released outside the responder's authorized incident scope.

Blue Force Bridge (BFB) — the responder workspace inside SOS

The complete responder-facing SOS environment: bounded incident information, scene intelligence, muster and route data, accountability and triage state, and — as one governed feature inside it — a consent-gated audio-request capability, the Tactical Audio Bridge (TAB). BFB decides nothing on its own; it is a bounded receiving/relay workspace that only displays what SOS, TSARO, and NICOLE Protocol have already cleared. Never continuous surveillance access.

What BFB receives

The bounded rescue packet NICOLE Protocol has approved for responder-scope release: SOS's minimized incident state, TSARO's admissibility result, CivOS's transport/availability state, and W-X environmental context where relevant.

What BFB does not receive by default

Unrestricted raw audio or video, continuous personal location history, unrelated historical data, full medical records, unrestricted biometric streams, permanent device access, or anything beyond the active incident's scope.

What BFB outputs

A responder-visible, scene-scoped workspace: bounded rescue information, muster and route intelligence, accountability/triage state, audit and handoff status.

Fail-closed behavior

No approved packet means BFB has nothing to show; it cannot query for more.

Tactical Audio Bridge (TAB) — consent-gated audio feature inside BFB

The Blue Force Bridge is the responder-facing SOS environment. The Tactical Audio Bridge is its consent-gated audio-request feature, connecting an authorized responder using BFB to the user's LAKANA device for a temporary, bounded audio session. TAB is not a peer system beside BFB, not a separate responder application, not a separate authority, and not interchangeable with BFB — it is one governed capability inside the BFB workspace, with its own consent, connection, session, and audit rules.

What TAB adds

A temporary, consent-gated audio-request mechanism from the responder's BFB interface to the user's device — nothing more.

What TAB does not add

An always-open microphone, passive listening, automatic responder audio access, permanent audio authority, unrestricted recording authority, voice-biometric identification, access to unrelated device audio, or authority outside the incident scope.

Relationship to NICOLE Protocol

A TAB session is a separate, additional NICOLE Protocol-scoped, time-boxed lease layered on top of the responder's BFB access — not implied by it.

Relationship to TSARO

A TAB session can only open on a distress state TSARO has already found admissible.

TAB request flow

  1. An authorized responder is already operating inside the BFB responder interface.
  2. BFB displays the incident information SOS, TSARO, and NICOLE Protocol have permitted for that responder's scope.
  3. The responder selects "Request Audio."
  4. BFB sends a bounded TAB request to the user's LAKANA device.
  5. The device clearly announces that emergency personnel are requesting an audio connection.
  6. The user is shown an unmistakable accept-or-deny interface — no live audio begins merely because the responder requested it.
  7. The user accepts through an approved interface, phrase, gesture, or other supported authorization method, or denies.
  8. NICOLE Protocol verifies responder identity, incident scope, user authorization, session duration, and revocation state.
  9. A separate, ephemeral audio session is created only if all of that verifies.
  10. The responder communicates through the TAB panel inside BFB; the user may disconnect or revoke at any time, and the session expires on its own bounded policy.
  11. Closing TAB does not destroy the responder's BFB incident workspace — BFB can remain active while TAB is inactive, denied, or closed.
  12. Every request, accept, deny, connect, disconnect, revoke, and expiry is written to the audit record.

BFB versus TAB under NICOLE Protocol: a responder may hold active BFB incident access while TAB remains unavailable, not requested, pending, denied, active, disconnected, revoked, or expired — each state tracked and audit-visible independently. BFB access is not TAB authorization.

Real-world scenario analogue
Structure fire, multi-occupant response
Situation
A multi-occupant structure fire; several residents remain inside as smoke conditions worsen, and one resident's phone detects a distress pattern.
Human actor
Civilian residents; multiple responding firefighters and EMS personnel using BFB.
Device / interface
Residents' phones; responders' BFB tablets.
What is observed
A rising distress signal from one unit, degraded egress-route conditions, and multiple occupants inside the structure.
What LAKANA computes
A minimized incident packet, admissible egress/muster candidates, and per-occupant accountability state.
Which authority evaluates it
TSARO (route/egress admissibility), NICOLE Protocol (release to responders), SOS (routing and minimization).
What is shown
Responders receive bounded scene state, muster points, accountability status per accounted occupant, and triage priority where applicable.
What is withheld
Continuous audio or video of residents, unrelated historical data, and any occupant's data outside this incident's scope.
What action LAKANA takes
Delivers only the minimized, cleared packet into BFB; offers TAB as a separate, occupant-authorized option per resident.
What remains a human decision
Responder tactical entry, search, and rescue decisions; each resident's decision to accept or deny a TAB session.
Failure behavior
Degraded transport preserves state locally and shows "preserving" rather than a false "delivered" state; ambiguous egress data holds rather than confidently routing occupants into an unverified path.
Current evidence level
Public Simulation / Receipt.
What would require field validation
Real multi-occupant incident testing with live fire-service coordination.
Test this scenario
Open SOS + CivOS simulation.
How SOS behaves under each CivOS energy mode
Normal
Full available public SOS capability.
Conserve
Reduced nonessential sensing and interface work; essential safety status preserved.
Critical
Essential local incident state only; explicit reduced capability shown to the user.
Emergency Burst
Time-bounded incident escalation, thermal- and energy-constrained.
Local-Preserve
Packet sealed locally; no false responder-delivery claim.
Recovery
Packet, lease and integrity reassessed before any delayed handoff.
Unavailable
Explicit unavailable state.
Responder-device degradation

When a BFB device loses transport: the display marks its state stale or unavailable; no new packet is claimed as received; locally held data remains bounded; NICOLE Protocol may expire the lease; TAB cannot initiate; and the audit record captures the affected state where available.

Multi-agency boundary

The architecture uses concepts such as accountability categories, muster points, handoff state and responder scope — NIMS/ICS-adjacent terminology for future mapping and external integration review. Formal integration with any incident-management standard, agency system or dispatch environment requires separate mapping, implementation and external review. No compatibility or compliance with any incident-management standard, emergency agency, or dispatch environment is claimed.

SSES evidence governance: MEBVBSPCSRET-BURDMCACSAFE-NELCISCLGTAF Claim posture: allowed statements are simulation-stage architecture and pathway evidence; stronger field/clinical/deployment statements are prohibited. Where a record is not yet complete: Public evidence record incomplete — Proof Library rebuild pending.
STRUCTURAL INTELLIGENCE · Consequence Authority

Sovereign Structural Intelligence (SSI)

Operating under the Physics-Sovereign Safety Paradigm (PSSP)

Turns load, fatigue, thermal pressure, and recovery into a bounded structural-pressure proxy for athletes and load-bearing workers — an engineering estimate, not a medical reading.

Consequence AuthorityEvidence: Public Simulation / Public Technical ManuscriptOperational: Public Interactive SurfaceStructural Load State
Refusal-state contract — what this design refuses to do
  • Does not diagnose
  • Does not make automatic eligibility decisions
  • Does not grant institutions ownership of raw biological history
Hard boundaryMay not diagnose, clear return-to-play, rank or compare people, or determine insurance/employment outcomes.
Human endpointAthlete/worker, coach, medical staff, researcher — see how information reaches the correct person for the full per-role device and receive-list.
Strongest non-claimNot medical diagnosis, not return-to-play authority, not clinical validation, no sex-superiority or performance-ranking claim.
Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
A structural-load and recovery proxy for a body — an engineering estimate, not a medical reading.
Why it exists
Raw sensor or load data, shown without interpretation, invites people to read it as a medical verdict it was never built to be.
Real-world failure it prevents
Raw sensor or load data being presented as a medical verdict instead of a bounded engineering proxy.
Authority it owns
A structural-pressure proxy ρ(t) and recovery-reserve estimate — descriptive state, nothing more.
Inputs
Load, fatigue, thermal pressure, damage memory, recovery reserve (Athlete Structural Twin) or compaction, posture, and repetition load (Occupational Structural Twins); W-X thermal/environmental context.
Governing mechanism
Ingest load/sensor state → validate against W-X truth where relevant → compute the pressure proxy → bound any recommendation through TSARO → scope the output by role through NICOLE Protocol.
Outputs
Pressure proxy, recovery-reserve estimate, thermal and damage indicators — role-scoped before delivery.
Human recipient / device
Athlete/worker, coach, medical staff, researcher — see how information reaches the correct person for the full per-role device and receive-list.
What it may do
Compute and display a bounded structural proxy; withhold on insufficient or contradictory input.
What it may not do
Diagnose, clear return-to-play, rank or compare people, or determine insurance/employment outcomes.
Dependencies
W-X (thermal/environmental context); TSARO bounds any downstream recommendation; NICOLE Protocol scopes who receives what.
Components it constrains
None it gates directly — its output feeds SSES only when someone chooses to publish it.
Components that constrain it
TSARO (any activity boundary is subject to TSARO's safe-set logic, not a clinical directive); NICOLE Protocol (role-scoped release — athlete/self versus institution/coach).
Normal operation
Continuous proxy computation from valid sensor/load input, refreshed on a bounded schedule.
Degraded operation
Insufficient or stale input withholds the proxy rather than estimating on weak data.
Adversarial / conflicting-input behavior
Contradictory sensor readings — for example a physically implausible load spike — are treated as low-confidence and withheld, not averaged into a falsely confident number.
Public-safe implementation pattern
Pressure proxy: ρ(t)=f(load, fatigue, thermal pressure, damage memory, recovery reserve). Proprietary weighting inside f is not disclosed.
Protected implementation boundary
Exact sensor-fusion weights, damage-memory decay curves, and twin-model internals remain undisclosed.
Current implementation
Public Simulation on ssi-models.html; Public Technical Manuscript via the SSI companion manuscripts on papers.html.
Maturity / evidence state
Public Simulation / Public Technical Manuscript (mixed by model).
Public non-claims
Not medical diagnosis, not return-to-play authority, not clinical validation, no sex-superiority or performance-ranking claim.
Open related evidence
SSI rows on evidence.html.
Canonical fragment ID
#ssi — preserved; the earlier standalone ssi.html route redirects to ssi-models.html.
Pressure proxy: ρ(t)=f(load, fatigue, thermal pressure, damage memory, recovery reserve)
Real-world scenario analogue
Warehouse worker, repetitive-load shift
Situation
A warehouse worker's repetitive lifting load approaches the modeled structural envelope over the course of a shift.
Human actor
Load-bearing worker; supervisor.
Device / interface
Worker's phone or wearable interface; supervisor's tablet (bounded summary only).
What is observed
A rising structural-pressure proxy and declining recovery reserve from the Occupational Structural Twin.
What LAKANA computes
Whether the proxy stays inside the safe envelope, and a role-scoped summary for the supervisor.
Which authority evaluates it
SSI computes the proxy; TSARO evaluates it against the safe set; NICOLE Protocol scopes what the supervisor sees.
What is shown
The worker sees a full personal proxy and recovery estimate; the supervisor sees only a bounded workload-envelope summary.
What is withheld
Raw biometric detail from the supervisor; any medical or clearance determination from either party.
What action LAKANA takes
Issues a bounded personal warning to the worker; the supervisor's view updates only to the authorized aggregate/summary level.
What remains a human decision
Whether the worker takes a break, and any workload or scheduling decision the supervisor makes.
Failure behavior
Withholds a confident estimate rather than guessing on ambiguous sensor input.
Current evidence level
Public Simulation.
What would require field validation
Clinical/occupational-health correlation with real injury outcomes.
Formal public structural contract — state space, envelope, contraction, dictionary, boundary

State space.

z_t ∈ Z

Variable dictionary. Public dimensions may include load, recovery, thermal pressure, strain accumulation, burden memory, gait or asymmetry state, observation quality, and time state.

Safe envelope.

C_t^SSI = { z : g_j(z) ≤ 0 }

Recalibration non-expansion.

R(C_t) = C_{t+1} ⊆ C_t

Assumptions. The declared safety-contraction condition holds for the recalibration operator R.

Public meaning. The public specification requires recalibration not to enlarge the admissible envelope under the declared safety-contraction assumptions.

Protected boundary. Physiological calibration curves, recovery constants, damage-decay constants, model coefficients, proprietary burden weights, raw biometric vectors, and personal baseline rules are not disclosed.

Non-claim: this specifies governing form; it is not a universal implementation proof, and implementation conformance requires separate verification.

How SSI behaves under CivOS energy constraint

Reduced sensor availability lowers confidence or withholds state rather than fabricating it. Local preservation remains possible. Coach and medical release cannot exceed current support. There is no false continuity during platform suspension, and energy conservation must not silently remove a safety-critical signal.

Lane integrity and managed-burden doctrine

The female lane, the male lane, and the occupational lane are each preserved as distinct analysis lanes. There is no forced pooling that hides materially different burden paths, and no demographic-superiority claim of any kind. Managed burden means a higher-burden pathway is surfaced and governed as a visible trade-off, never silently averaged away.

SSES evidence governance: MEBVBSPCSRET-BURDMCACSAFE-NELCISCLGTAF Claim posture: allowed statements are simulation-stage architecture and pathway evidence; stronger field/clinical/deployment statements are prohibited. Where a record is not yet complete: Public evidence record incomplete — Proof Library rebuild pending.
ENVIRONMENTAL TRUTH · Truth Authority

Weather Exchange (W-X)

The environmental truth, freshness, consistency, drift, uncertainty, and temporal-validity authority — decides whether a reading is admissible as truth right now, and lets it decay to silence instead of staying "true" forever.

Truth AuthorityEvidence: Public SimulationOperational: Public Interactive SurfaceEnvironmental Ground Truth
Refusal-state contract — what this design refuses to do (W-X / WX-Ag)
  • Does not replace official weather authority
  • Does not issue farm directives
  • Does not guarantee yield
Hard boundaryMay not interpret what a reading means for a person or field — that is SSI's and WX-Ag's job — or decide whether an action is safe (TSARO).
Human endpointPhone, tablet, desktop, or local node interface — see how information reaches the correct person for the full field list shown at each interface.
Strongest non-claimW-X does not replace or override official radar, Mesonet, or NWS warnings; not a certified meteorological authority.

W-X public states: Supported · Degraded · Contradictory · Drifting · Quarantined · Expired · Silent.

W-X is complementary ground-layer and source-authority infrastructure. It does not replace official weather warnings, radar, Mesonet observations, meteorologists or public agencies.

Formal public truth contract — claim object, TTL, inertial consistency, dictionary, boundary

Environmental claim object.

e_t = ( v_t, u_t, t₀, q_t, c_t ) ∈ E

Variable dictionary. v_t — observed value; u_t — unit; t₀ — observation time; q_t — source class; c_t — context class.

Temporal validity (TTL).

D(t) = 1 if t − t₀ < τ, else 0 D(t) = 0 ⇒ e_t → ∅

Expired information may remain in historical storage, but it must not retain current authority.

Abstract inertial consistency.

‖ x_reported − x_inertial ‖ ≤ ε_x | h_reported − h_barometric | ≤ ε_h

Assumptions. Cross-source agreement is evaluated over sources of a declared class; consistency bounds apply to the declared observation families.

Public meaning. A reading is admissible only while fresh, physically consistent, and corroborated; otherwise it decays to degraded, quarantined, expired, or silent.

Protected boundary. The values of ε_x and ε_h, TTL values, agreement thresholds, sensor-fusion weights, drift filters, anti-spoof thresholds, spatial interpolation, noise models, calibration internals, and the source-selection hotpath are not disclosed.

Non-claim: this contract classifies environmental support; it is not an official warning capability and carries no forecast guarantee.

Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
The authority that decides whether an environmental reading is fresh, physically consistent, and corroborated enough to be treated as real right now.
Why it exists
Every downstream consequence model — SSI's thermal term, WX-Ag's field burden, TSARO's admissibility checks — needs to know whether the environmental input it's using is still true, not just whether it was true when it arrived.
Real-world failure it prevents
Treating stale, missing, or contradicted environmental data as current fact.
Authority it owns
Freshness, physical-consistency, mesh-agreement, drift, and temporal-validity determination for environmental readings; the decision to let a reading expire to silence.
Inputs
Raw node/sensor observations, observation timestamps, source class, mesh/cross-station agreement, physical-consistency bounds.
Governing mechanism
Check observation age against TTL → check physical plausibility → check cross-source agreement → classify admissible / degraded / quarantined / expired → expose the classification, not just the raw value.
Outputs
An admissible reading with age/TTL/agreement metadata, or a quarantined/expired/silent state — never a stale value presented as current.
Human recipient / device
Phone, tablet, desktop, or local node interface — see how information reaches the correct person for the full field list shown at each interface.
What it may do
Admit, degrade, quarantine, expire, or silence a reading based on freshness and consistency.
What it may not do
Interpret what a reading means for a person or field — that is SSI's and WX-Ag's job — or decide whether an action is safe (TSARO).
Dependencies
CivOS substrate (a sensor needs power/transport to report at all); Sovereign Root indirectly, for any personally-scoped environmental data.
Components it constrains
SSI (thermal-pressure term); WX-Ag, which must wait on admissible W-X input before interpreting it; TSARO, which evaluates against admissible truth only.
Components that constrain it
CivOS substrate availability bounds what W-X can even observe.
Normal operation
Continuous freshness/consistency evaluation; readings admitted while inside TTL and agreement bounds.
Degraded operation
Readings approaching TTL are marked aging/degraded before they expire outright, giving downstream consumers advance warning.
Adversarial / conflicting-input behavior
A node reporting outside physically plausible bounds, or disagreeing sharply with corroborating sources, is quarantined rather than averaged in.
Public-safe implementation pattern
Admissibility gate: a reading is admissible only while age ≤ TTL, cross-source agreement holds, and the value stays within physically plausible bounds; otherwise it decays to degraded, quarantined, or silent. Exact TTL values and agreement thresholds are not disclosed.
Protected implementation boundary
Exact TTL values, agreement thresholds, and node-trust weighting are not disclosed.
Current implementation
Public Simulation on wx-weather-metrology-model.html and environmental-model.html.
Maturity / evidence state
Public Simulation.
Public non-claims
W-X does not replace or override official radar, Mesonet, or NWS warnings; not a certified meteorological authority.
Open related simulation
wx-weather-metrology-model.html.
Open related evidence
environmental-model.html.
Canonical fragment ID
#w-x — new addressable element in this rebuild; previously referenced by other sections but not itself an anchorable id.
Real-world scenario analogue
Severe-weather ground-truth check
Situation
A severe storm cell approaches; multiple ground nodes report conflicting rainfall and wind readings.
Human actor
Civilian user checking local conditions; WX-Ag operators depending on the same feed.
Device / interface
Phone/tablet weather view; local node interface.
What is observed
Disagreement between neighboring mesh nodes and a reading outside recent physical bounds.
What LAKANA computes
Cross-source agreement and physical-consistency checks on the disputed reading.
Which authority evaluates it
W-X itself — this is the authority being exercised, not a downstream consumer.
What is shown
The disputed node's reading marked degraded/quarantined; the agreeing consensus reading shown as admissible.
What is withheld
Any single-source reading presented as confirmed truth while it is still in disagreement.
What action LAKANA takes
Quarantines the outlier reading, keeps serving the corroborated value, and flags the quarantine state to downstream consumers.
What remains a human decision
Whether to also consult official radar, Mesonet, or NWS channels, which W-X never claims to replace.
Failure behavior
Silence/quarantine rather than presenting an unresolved conflict as settled fact.
Current evidence level
Public Simulation.
What would require field validation
Real mesh-network deployment across varied terrain and hardware.
Test this scenario
Test W-X mesh agreement.
AGRONOMIC CONSEQUENCE · Consequence Authority

Weather Exchange Agronomic Extension (WX-Ag)

The field-facing agronomic extension that turns W-X-supported environmental state into bounded soil, water, crop, root-zone, evapotranspiration, saturation, anoxia, heat, cold, and agronomic-stress interpretations. Not an independent weather authority.

Consequence AuthorityEvidence: Public SimulationOperational: Public Interactive SurfaceAgricultural Field State
Hard boundaryMay not predict yield, set insurance or lender status, or tell a farmer what to do next.
Human endpointField operator/farmer on phone, tablet, or desktop — see how information reaches the correct person.
Strongest non-claimNo yield guarantee, no farm directive, no insurance or lender score.

W-X determines whether environmental state is sufficiently supported. WX-Ag determines what that accepted or explicitly degraded state may mean for a field, soil profile, crop stage and root zone.

ET₀ source-class contract and public model paths

ET₀ source class.

q_ET₀ ∈ { internal empirical compute, external runtime support, validation-only, unsupported }

Public internal empirical path — Hargreaves-Samani / FAO-56 Equation 52 public internal empirical path:

ET₀ = 0.0023 · R_a · (T_mean + 17.8) · √(T_max − T_min)

Higher-input reference path. Penman-Monteith is a higher-input reference or supported pathway where the required meteorological terms are available — it is not presented as the always-active runtime hotpath:

ET₀ ≈ [0.408Δ(Rn−G) + γ(900/(T+273))u₂(es−ea)] / [Δ + γ(1+0.34u₂)]

VPD.

VPD = es(T) · (1 − RH/100)

Soil-water balance (abstract loss term L_t):

D_t = D_{t−1} + K_c·ET₀ − R_t − I_t + L_t

Root-zone oxygen-deficit proxyproxy, field validation required:

RZOD(t) = ∫ max( 0, θ_root(t) − θ_aer ) dt

Variable dictionary. R_a — extraterrestrial radiation; T_mean/T_max/T_min — temperature terms; D_t — cumulative water deficit; K_c — crop coefficient class; R_t — rainfall; I_t — irrigation; L_t — abstract loss term; θ_root — root-zone water content; θ_aer — aeration boundary.

Public meaning. The source class travels with every ET₀ value, so a consumer always knows whether the number came from the internal empirical path, external runtime support, or validation-only comparison.

Protected boundary. Exact source selection, fallback, filtering, calibration, energy-bound execution and runtime hotpath remain protected.

Non-claim: WX-Ag may compute a simulator-defined yield proxy or modeled yield potential under declared assumptions. It may not present that output as a real-world field forecast, guaranteed yield, crop-loss certification, insurance basis, lending determination or agronomic directive.

Architecture contract — full definition, inputs, outputs, dependencies, behavior

Definition and role

Plain-meaning definition
A field-specific burden model — ET₀, root-zone pressure, drought/heat/cold envelope — built on top of, and never ahead of, W-X ground truth.
Why it exists
Blending agricultural interpretation into raw environmental truth would force W-X itself to start making farm-directive claims; keeping them separate lets each stay in its lane.
Real-world failure it prevents
Presenting agricultural interpretation as if it were raw environmental truth, or vice versa.
Authority it owns
Field-zone burden proxies: ET₀, VPD, root-zone pressure, drought/heat/cold envelopes.
Inputs
Rainfall, irrigation, ET₀ inputs, soil moisture, drainage, compaction, crop growth stage, W-X node truth (TTL, mesh agreement, drift).
Governing mechanism
Require admissible W-X input → compute field-zone burden proxies → bound any exported manifest → route export through NICOLE Protocol ledgering.
Outputs
Descriptive field-state metrics and a bounded, exportable manifest.
Human recipient / device
Field operator/farmer on phone, tablet, or desktop — see how information reaches the correct person.
What it may do
Compute and display bounded burden proxies; export a ledgered manifest.
What it may not do
Predict yield, set insurance or lender status, or tell a farmer what to do next.
Dependencies
W-X — its input must be admissible before WX-Ag interprets it.
Components it constrains
None it gates directly — feeds SSES only when someone chooses to publish it.
Components that constrain it
W-X admissibility; NICOLE Protocol for manifest-export ledgering.
Normal operation
Continuous burden-proxy computation from admissible W-X input.
Degraded operation
Inadmissible W-X input withholds the burden estimate rather than extrapolating past it.
Adversarial / conflicting-input behavior
Contradictory soil or rainfall telemetry is treated as low-confidence and withheld rather than blended into a falsely precise number.
Public-safe implementation pattern
ET₀ carries an explicit source class (internal empirical compute / external runtime support / validation-only / unsupported); the public internal empirical path is Hargreaves-Samani / FAO-56 Equation 52, with Penman-Monteith as a higher-input reference or supported pathway when the required meteorological terms are available. VPD = es(T) · (1 - RH/100); Root-zone pressure = f(WaterBalance, ET₀, drainage, compaction, crop stage). See the ET₀ source-class contract above.
Protected implementation boundary
Exact drainage/compaction weighting and crop-stage curves are not disclosed.
Current implementation
Public Simulation on wx-ag-farmer-model.html.
Maturity / evidence state
Public Simulation.
Public non-claims
No yield guarantee, no farm directive, no insurance or lender score.
Open related simulation
wx-ag-farmer-model.html.
Open related evidence
environmental-model.html.
Canonical fragment ID
#wx-ag — preserved.
ET₀ (public internal empirical path): ET₀ = 0.0023·R_a·(T_mean+17.8)·√(T_max−T_min) VPD = es(T) · (1 - RH/100) Root-zone pressure = f(WaterBalance, ET₀, drainage, compaction, crop stage)
Real-world scenario analogue
Root-zone anoxia risk after heavy rainfall
Situation
Heavy rainfall saturates a field; root-zone anoxia risk rises for a sensitive crop stage.
Human actor
Farmer / field operator.
Device / interface
Phone/tablet WX-Ag view.
What is observed
Rising saturation and a declining root-zone oxygen proxy, built on admissible W-X rainfall/soil readings.
What LAKANA computes
Field-zone burden proxies — saturation, anoxia proxy, drainage-adjusted water balance.
Which authority evaluates it
WX-Ag computes the burden proxy; W-X admissibility gates its inputs; TSARO's fail-closed-on-inadmissible-truth pattern still applies to the underlying reading.
What is shown
A bounded burden/anoxia-risk indicator and the underlying admissible W-X readings it was built from.
What is withheld
Any yield prediction, insurance/lender signal, or directive telling the farmer what to do.
What action LAKANA takes
Surfaces the descriptive burden state and exports a bounded, NICOLE Protocol-ledgered manifest if the farmer chooses to export it.
What remains a human decision
Whether and how the farmer responds — drainage, timing, or no action.
Failure behavior
Withholds the burden estimate if the underlying W-X input is inadmissible, rather than extrapolating past it.
Current evidence level
Public Simulation.
What would require field validation
Real multi-season field agronomy validation against actual crop outcomes.
Test this scenario
Test the WX-Ag farmer model.

Cross-System Map

One interactive view of the whole architecture. Every node is a real link to that system's chapter; with JavaScript enabled, activating a node opens an inspector summary instead of jumping, and the filters and scenario overlays below highlight subsets of the map. The architecture-in-one-view section above is the complete text equivalent of this diagram.

Refusal-state contract — what this map refuses to do
  • Does not show live telemetry
  • Does not imply every gate is universal
  • Does not imply the operational lanes depend on one another
LAKANA cross-system architecture map Sovereign Root sits above CivilizationOS as the shared foundation. TSARO and NICOLE Protocol are conditionally invoked operational authorities. Three independent operational lanes run on the foundation: SOS containing the Blue Force Bridge which contains the Tactical Audio Bridge; SSI; and W-X feeding optional WX-Ag. The NICOLE Protocol governance rail runs inside the operational lanes. Human endpoints receive bounded outputs. Public-safe released artifacts pass the SSES evidence-adjudication perimeter into the Proof Library. A full text equivalent appears in the architecture-in-one-view section. Sovereign Root CivilizationOS (CivOS) TSARO NICOLE Protocol SOS — Safety Operating System Blue Force Bridge (BFB) Tactical Audio Bridge (TAB) SSI — Sovereign StructuralIntelligence W-X — Weather Exchange WX-Ag (optional) Human endpoints — civilian · responder · athlete · coach · medical · operator · farmer · researcher Public-safe released artifacts → SSES evidence-adjudication perimeter Proof Library

Independent-lane locks: SOS does not require SSI or WX-Ag. SSI does not require SOS or WX-Ag. W-X/WX-Ag does not require SOS or SSI. Cross-lane context, where used, is optional.

Cross-lane degraded-state matrix

What actually happens, lane by lane, when a resource, consent, integrity, or input condition degrades. In every row the human sees an explicit state — never a silently faked normal one.

ConditionFirst authority to actCivOS stateTSARO responseNICOLE Protocol responseDomain responseHuman-visible resultAudit / preservation
Battery budget pressureCivOSConserve or CriticalUnchanged unless physical state changesUnchangedNonessential work reduced in priority order"Capability reduced"Mode transition recorded
Thermal pressureCivOSConserve or CriticalUnchangedUnchangedVisible throttling; essential status preserved"Capability reduced (thermal)"Mode transition recorded
Memory/storage pressureCivOSConstrained storage modeUnchangedRetention policy enforcedBatched writes; bounded retention"Storage constrained"Event commitment preserved
Sensor unavailableCivOSCapability vector reducedSafe set evaluated on remaining inputsUnchangedDependent state withheld, not fabricated"Signal unavailable"Availability change recorded
Sensor quality degradedCivOS / domainQuality-flaggedHold or degrade where relevantUnchangedConfidence lowered or state withheld"Reduced confidence"Quality state recorded
Transport unavailableCivOSLocal-PreserveNo false delivery pathNo external releasePreserve locally"Preserved locally; not delivered"Local event commitment
Platform suspendedCivOSUnavailableNot evaluatedLeases expire on their own boundariesNo false continuity claimedExplicit unavailability where possibleSealed state preserved where possible
Consent deniedNICOLE ProtocolCapability unchangedUnchangedDeny; log the denialNo scoped release begins"Access denied"Denial event
Consent revokedNICOLE ProtocolCapability unchangedUnchanged unless physical path changesTerminate leaseScoped release stops"Access revoked"Revocation event
Lease expiredNICOLE ProtocolCapability unchangedUnchangedExpire; deny further accessScoped release stops"Access expired"Expiry event
Integrity mismatchNICOLE ProtocolIntegrity-flaggedHold dependent admissibilityIntegrity-failed; denyDependent output withheld"Integrity unavailable"Integrity event
Contradictory environmental inputW-XCapability unchangedContract or hold where relevantDoes not release unsupported derived stateWX-Ag withholds consequence"Source contradiction; result unavailable"Contradiction state recorded
Responder interface degradedCivOS (responder device)Stale/unavailable display stateUnchangedMay expire the lease; TAB cannot initiateNo new packet claimed as received"Responder view stale/unavailable"Affected state recorded where available

Public authority interface contracts

For every authority: what it accepts, what it emits, and what it is forbidden to decide. SSES appears here as the public evidence perimeter — it is not one of the seven operational authority types, but its public evidence contract is stated the same way.

Sovereign Root — Constitutional Authority
AcceptsUser policy, purpose, role doctrine, emergency doctrine, revocation policy
EmitsGoverning policy state
Forbidden to decidePhysical truth, domain interpretation, public evidence adjudication
CivOS — Substrate Authority
AcceptsResource state, platform state, hardware capability
EmitsCapability state, operating mode, local preservation state
Forbidden to decideMedical meaning, environmental truth, release authorization
W-X — Truth Authority
AcceptsEnvironmental observations, source metadata, time state
EmitsSupported / degraded / expired environmental state
Forbidden to decideAgronomic consequence, official public warning, personal release authority
SSI / WX-Ag — Consequence Authority
AcceptsAdmissible domain inputs
EmitsBounded domain consequence
Forbidden to decideTruth creation, custody authorization, medical or farm directive
TSARO — Admissibility Authority
AcceptsState, proposed output/action, uncertainty
EmitsAdmissibility class, contracted safe set
Forbidden to decideIdentity, consent, release, public scientific claim
NICOLE Protocol — Custody Authority
AcceptsRole, purpose, scope, lease, integrity, approval, revocation
EmitsPermit, deny, narrow, expire, revoke, custody/audit state
Forbidden to decidePhysical truth, diagnosis, public evidence validity
SOS — Coordination Authority (BFB as responder interface)
AcceptsMinimized admissible incident state, valid release scope
EmitsCivilian safety presentation, BFB handoff, optional TAB request
Forbidden to decideOfficial dispatch authority, unbounded surveillance, automatic audio access
SSES — Public Evidence Adjudication Perimeter
AcceptsPublic-safe released artifact, claim, source lineage, limitations
EmitsAllowed claim, forbidden claim, evidence maturity, hold/downgrade/withhold state
Forbidden to decideOperational release, consent decisions, field validation claims

Public disclosure boundary — what is published, what is protected

Public equations describe governing mathematical form, state classes and authority boundaries. Exact coefficients, thresholds, timing policies, sensor-fusion weights, key-derivation contexts, hardware mappings, private datasets and reconstructive implementation details remain protected. This matrix states the boundary per component so a reviewer never has to guess whether an omission is an oversight or a decision.

CivOS
Public-safeState-space dimensions, operating modes, capability contraction, abstract resource inputs, abstract transport state, fail-closed transition classes, local preservation state
ProtectedComparator values, voltage values, hardware mappings, register masks, scheduler thresholds, interrupt logic, exact power budgets, exact battery thresholds, actual sensor schedules, actual transport selection
TSARO
Public-safeState space, input space, safe-set definition, admissibility states, projection form, uncertainty contraction, constraint classes
ProtectedConstraint coefficients, risk weights, trust weights, policy matrices, real-time threshold maps, actuator mappings, proprietary optimization matrices
SOS
Public-safeIncident-state workflow, minimization contract, civilian interface, the BFB-contains-TAB hierarchy, degraded-state behavior, route/muster/accountability categories, release-state classes
ProtectedTrigger logic, responder-selection and matching logic, minimization thresholds, escalation heuristics, internal route scoring, actual emergency packet schema
NICOLE Protocol
Public-safeRole/scope/purpose/lease model, permit relation, hash-chain abstraction, key-separation doctrine, expiration state, revocation flow, evidence-capsule field classes, commitment-tree abstraction
ProtectedRoot-key layout, derivation contexts, salts, key slots, enclave addresses, memory-clearing routines, actual cryptographic secrets, real custodian maps, real quorum values
W-X
Public-safeEnvironmental claim object, freshness, TTL, source class, agreement, contradiction, drift, uncertainty, abstract inertial consistency bounds
ProtectedSensor-fusion weights, drift filters, anti-spoof thresholds, spatial interpolation, noise models, calibration internals, source-selection hotpath
WX-Ag
Public-safeET₀ source classes, public ET₀ equation path, VPD, soil-water balance, root-zone state, saturation/anoxia proxy, crop-stage context, yield-proxy boundary, uncertainty classifications
ProtectedExact hotpath, crop calibration curves, drainage coefficients, empirical ingestion logic, threshold values, field interpolation, proprietary agronomic weights
SSI
Public-safeStructural-state dimensions, load/recovery abstraction, thermal and burden state, monotone envelope doctrine, role-specific output classes, lane-integrity rules
ProtectedPhysiological baselines, model coefficients, recovery constants, damage-decay constants, calibration procedures, raw biometric vectors, proprietary damage weights
SSES
Public-safeExact eight-layer names, purpose of every layer, public formula classes, allowed interpretation, forbidden interpretation, branch examples, claim-status classes
ProtectedInternal weighting, private claim registry, unpublished adjudication rules, private artifacts, internal evidence-processing logic

Critical distinctions

These ten pairs are the ones visitors most often collapse into each other. Each one is a deliberate, load-bearing boundary — not a naming accident.

W-XEnvironmental ground truth: is this reading fresh, consistent, and corroborated right now?
vs
WX-AgAgricultural consequence: what does that truth mean for this specific field's crop and soil?
Kept separate so the agricultural model can go deep on crop physics without W-X itself starting to make farm-directive claims.
TSARODecides whether an action is physically safe under uncertainty. Never releases anything itself.
vs
NICOLE ProtocolDecides who may see or hold data that TSARO has already found admissible. Never judges physical safety.
Safety and custody are different questions with different failure modes; collapsing them would let a "safe" action bypass access control, or an "authorized" viewer see something physically unverified.
CivOSSubstrate authority: is there enough power, storage, and transport to run at all?
vs
SOSCoordination authority built on top of CivOS: how does bounded help reach a responder?
CivOS has no concept of "rescue" — it only knows whether the lights are on. SOS is one of several services that depend on CivOS being up.
SSIA structural-pressure engineering proxy built from load, fatigue, and recovery inputs.
vs
Medical diagnosisA clinical determination made by a licensed professional using validated clinical instruments.
SSI is not clinically validated and does not claim to be. It is not return-to-play authority and should never be treated as one.
SOSA bounded civilian-safety coordination architecture, currently a research/simulation candidate.
vs
911 / official emergency servicesCertified, legally mandated, professionally staffed dispatch.
SOS is not a replacement for 911, emergency managers, or professional responders under any circumstance shown on this site.
BFBThe complete responder-facing SOS workspace — the container and responder environment.
contains
Its TAB featureThe consent-gated audio-request capability inside that workspace — one controlled capability, not a peer system.
BFB can operate without an active TAB session. TAB cannot operate outside an authorized BFB incident context. The relationship is hierarchical, not two coordinate systems joined by a slash.
BFB accessPermits a responder to view only the bounded incident information already authorized for that responder role.
TAB consentSeparately permits a temporary live audio session — its own authorization event.
One does not imply the other. A responder may hold active BFB access while TAB remains unavailable, not requested, pending, denied, active, disconnected, revoked, or expired — TAB carries its own state, independent of BFB's.
NICOLE ProtocolAn internal governance and audit design pattern: role, scope, consent, epoch, revocation, audit.
vs
A formal privacy certificationAn external regulatory or legal attestation (e.g. a compliance audit by a certifying body).
NICOLE Protocol is architecture, not paperwork. It is not represented as a substitute for whatever formal certification a given deployment context actually requires.
SSESEight post-run evidence-governance layers applied after a simulation already produced its result. The domain model creates the result. SSES adjudicates what the completed public-safe artifact is allowed to support publicly.
vs
A marketing claimA promotional statement optimized to persuade rather than to stay inside tested evidence.
If a statement about LAKANA can't be traced to a labeled, bounded artifact in the Proof Library and cleared through SSES's eight layers, this page treats it as not yet true rather than probably true.
Fail-closedTSARO's default: when admissibility can't be confirmed, the system does nothing rather than guess.
vs
Fail-openA system that keeps acting, or keeps a channel open, by default when it loses certainty.
LAKANA deliberately refuses fail-open behavior everywhere a physical or custody decision is uncertain — silence is treated as safer than a wrong guess.

State lifecycle: shared spine, conditional branches

LAKANA uses a shared processing grammar with conditionally invoked authorities. Domain, data class, purpose, operating state, and intended recipient determine which authorities must act — no universal staircase exists, not every state uses every gate, and multiple compatible outcomes may occur for the same piece of state (for example local display together with local preservation and an audit entry).

Shared processing grammar — stages invoked where applicable

Stage 1Observe / receiveRaw signal is captured or asserted at a node, subject to CivOS substrate availability.
Stage 2Authenticate / source-classifyThe source and its identity are classified before anything is trusted.
Stage 3Preserve & operate (CivOS)State is held locally under CivOS's current degraded or normal mode.
Stage 4Validate relevant truthWhere applicable, W-X checks freshness, physical consistency, and mesh agreement.
Stage 5Compute domain stateThe relevant lane — SOS, SSI, or W-X/WX-Ag — turns validated input into domain-specific state.
Stage 6Evaluate admissibilityTSARO checks the resulting state against the safe set; admits, contracts, or fails closed.
Stage 7Minimize outputOnly what a specific role or purpose actually needs survives to this point.
Stage 8Apply NICOLE Protocol policyNICOLE Protocol checks role, scope, consent/lease, epoch, and revocation before anything moves further.

Conditional outcome branches

One or more compatible outcomes follow for a given piece of state — never all of them, and never in a fixed universal order. Local display, local preservation, authorized role display, BFB handoff, audit entry, aggregate preparation, SSES adjudication, and Proof Library registration can co-occur where their separate conditions are each satisfied:

Local user display Authorized role display SOS responder handoff Local preservation without release Public evidence publication Denial Quarantine Expiration Revocation Silence

SOS responder-handoff path Not the universal LAKANA lifecycle — this is what the "SOS responder handoff" branch above actually does, and it applies only when that specific branch is taken.

  1. Route the authorized responder handoff to BFB.
  2. BFB incident workspace
    • Display bounded rescue information
    • Display muster and route intelligence
    • Display accountability or triage state
    • Send permitted tactical notice
    • Request optional TAB audio session
      • Await user authorization
      • Connect temporarily
      • Deny
      • Disconnect
      • Revoke
      • Expire

TAB is not a universal lifecycle stage. It occurs only when a verified responder requests audio, audio is relevant and available, the request is within incident scope, the required authorization condition is satisfied, NICOLE permits the session, and the device and network can support it.

Operational walkthroughs

Ten concrete scenarios, each answered against the same eleven questions, so the authority stack above can be checked against real situations instead of staying abstract. These are simulation-bound walkthroughs describing how the bounded model behaves — not field reports.

1. Athlete structural-load walkthroughSSI · Athlete Structural Twin
  1. TriggerAn athlete's load session (practice or competition) pushes cumulative load and thermal pressure upward on the Athlete Structural Twin.
  2. First sensedLoad, fatigue, thermal pressure, and recovery-reserve inputs on the SSI panel.
  3. Truth authorityW-X supplies ambient thermal/environmental context feeding the thermal-pressure term.
  4. Consequence interpretationSSI computes the pressure proxy ρ(t) from load, fatigue, thermal pressure, damage memory, and recovery reserve.
  5. TSAROChecks whether the resulting proxy state stays inside the defined safe set for continued activity modeling; contracts toward the safe set or flags infeasibility.
  6. NICOLE gateChecks whether the requester (athlete/self vs. institution/coach) has a valid role and scope before the proxy is shown.
  7. Receives outputThe athlete, or a coach/institution role scoped explicitly to aggregate/envelope data only — never raw trajectories.
  8. WithheldAny near-clinical feed, raw biometric trajectory, or behavioral profile stays withheld regardless of role.
  9. Fail-closedContradictory or insufficient load input withholds the proxy rather than estimating on weak data.
  10. RecordedThe proxy computation and the role-scope check are both NICOLE-ledgered.
  11. Public non-claimNot medical diagnosis, not return-to-play authority, not clinical validation.
2. Occupational worker structural walkthroughSSI · Occupational Structural Twins
  1. TriggerA shift's repetitive lifting, posture, and compaction load accumulate on an Occupational Structural Twin.
  2. First sensedRepetition load, posture angle, compaction, and recovery inputs.
  3. Truth authorityW-X supplies environmental context (heat/cold burden on the worker) where relevant.
  4. Consequence interpretationSSI computes an occupational structural-pressure proxy using the same ρ(t) family of inputs, tuned for workplace load rather than athletic load.
  5. TSAROEvaluates whether the resulting occupational-pressure state remains inside the modeled safe set for continued task load.
  6. NICOLE gateChecks whether the requester (worker/self vs. employer/safety officer role) has valid scope.
  7. Receives outputThe worker, or an employer/safety-officer role scoped to aggregate envelope data only.
  8. WithheldIndividual raw posture/load trajectories are withheld from the employer role; only bounded envelope summaries are ever exposed.
  9. Fail-closedAmbiguous or missing posture/load data withholds the proxy instead of guessing at fatigue state.
  10. RecordedProxy computation and role-scope check are NICOLE-ledgered.
  11. Public non-claimNot a workers'-compensation determination, not an employment or fitness-for-duty ruling, not clinical validation.
3. Flash-drought farmer walkthroughWX-Ag · Farmer Model
  1. TriggerRising ET₀ and falling soil moisture on the Farmer Model's "Flash drought" scenario.
  2. First sensedRainfall, irrigation, ET₀, temperature, humidity, wind, solar, and soil-moisture sliders.
  3. Truth authorityW-X mesh agreement and TTL determine whether the underlying node readings are admissible.
  4. Consequence interpretationWX-Ag computes Penman-Monteith ET₀, VPD, and a drought-deficit proxy for the field zone.
  5. TSARONot directly gating (no physical actuation); the fail-closed-on-inadmissible-truth pattern still applies to the underlying W-X input.
  6. NICOLE gateChecks role/scope before the bounded farmer manifest can be exported.
  7. Receives outputThe farmer, via the on-screen field-state metrics and an optional exported manifest.
  8. WithheldNo yield number, no insurance/lender score, no directive action — only descriptive physical state.
  9. Fail-closedStale or low-agreement node readings drop the drought-deficit estimate to withheld rather than displaying a stale figure.
  10. RecordedManifest exports are written to the NICOLE-governed farmer ledger.
  11. Public non-claimNo yield guarantee, no farm directive, no insurance/lender score.
4. Flood / root-anoxia farmer walkthroughWX-Ag · Farmer Model
  1. TriggerSaturated soil and weak drainage on the Farmer Model's "Flood / root anoxia" scenario.
  2. First sensedSoil moisture, drainage percentage, compaction, and root-depth sliders.
  3. Truth authorityW-X freshness/consistency check on the underlying soil and rainfall telemetry.
  4. Consequence interpretationWX-Ag computes a root-zone pressure and anoxia proxy from the water balance, drainage, and compaction terms.
  5. TSARONo physical actuation to gate; the underlying truth-admissibility fail-closed pattern still applies.
  6. NICOLE gateChecks role/scope before manifest export.
  7. Receives outputThe farmer, via field-state metrics and optional manifest export.
  8. WithheldNo crop-loss dollar figure, no directive to replant or file a claim.
  9. Fail-closedContradictory drainage/compaction input withholds the anoxia estimate rather than guessing.
  10. RecordedManifest exports are NICOLE-ledgered.
  11. Public non-claimNo yield guarantee, no farm directive, no insurance/lender score.
5. Severe-weather ground-truth walkthroughW-X · Weather / Metrology Model
  1. TriggerA ground mesh node reports a reading that diverges from neighboring nodes during a fast-moving weather event.
  2. First sensedNode telemetry, GPS/IMU cross-check, RF noise, and mesh-agreement inputs.
  3. Truth authorityW-X itself is the authority being exercised: it checks TTL, physical admissibility, and node agreement.
  4. Consequence interpretationNone yet at this stage — W-X only establishes whether the reading is admissible truth, before any consequence model touches it.
  5. TSAROTreats a low-agreement or expired reading as an automatic infeasibility condition for anything downstream that depends on it.
  6. NICOLE gateLocation-adjacent node data is custody-scoped before any output leaves the model.
  7. Receives outputA visitor viewing the Weather Model's bounded fit-to-Mesonet/radar comparison, not a warning authority.
  8. WithheldNo official warning is issued or implied; raw node-location trails are not exposed.
  9. Fail-closedA diverging or stale node reading decays to null and is excluded from the displayed truth state.
  10. RecordedNode-state transitions are logged for the model's internal audit trail.
  11. Public non-claimNot an official weather-warning system; does not replace radar, Mesonet, or NWS.
6. SOS responder handoff via BFB, with an optional nested TAB requestSOS · BFB · TAB (a BFB feature)
  1. TriggerA civilian distress state is detected in the SOS lab's Monte Carlo run; an authorized responder is already operating inside the BFB responder interface.
  2. First sensedLocal device/state signals feeding SOS's local-state assessment.
  3. Truth authorityW-X supplies any environmental context relevant to the distress state (e.g. location admissibility).
  4. Consequence interpretationSOS minimizes local state to the smallest packet that could be useful to a responder.
  5. TSAROConfirms the minimized state and any proposed release stay inside the safe set before anything is queued.
  6. NICOLE gateAuthorizes the responder's BFB scope — scene-scoped by default — and, only if separately requested and accepted, a distinct time-boxed TAB audio lease layered on top of that same access.
  7. Receives outputThe responder, via the BFB workspace: bounded rescue information, muster/route intelligence, and accountability state. If the responder selects "Request Audio," the user's device announces the request and shows an accept/deny interface; only user acceptance opens an ephemeral TAB session inside BFB.
  8. WithheldContinuous location tracking, raw device state, anything outside the bounded rescue packet, and any audio at all unless the user separately accepts the TAB request — BFB authorization is not TAB authorization.
  9. Fail-closedIf TSARO or NICOLE do not clear release, BFB shows nothing; if TAB consent is missing, denied, or expired, no audio connects regardless of BFB's own active state.
  10. RecordedThe BFB packet delivery and every TAB event — request, accept, deny, connect, disconnect, revoke, expiry — are separately NICOLE-ledgered.
  11. Public non-claimNot emergency certification, not official dispatch, not a guaranteed rescue; TAB is not an always-on microphone and does not open merely because a responder has BFB access.
7. CivOS degraded-power fail-closed walkthroughCivOS · TSARO
  1. TriggerPower or transport availability drops below the threshold CivOS needs for full operation.
  2. First sensedPower state, storage state, and transport availability telemetry.
  3. Truth authorityW-X readings may still be arriving, but their admissibility is now bounded by CivOS's degraded substrate.
  4. Consequence interpretationNo consequence model (SSI/WX-Ag) proceeds past this point until substrate is confirmed sufficient.
  5. TSAROCan independently force fail-closed on any pending action regardless of CivOS's own degraded-mode selection.
  6. NICOLE gateThe degraded-mode transition itself is logged, not gated (there is nothing to release yet).
  7. Receives outputNo end user receives a live output during this state; the system enters local-only or silent mode.
  8. WithheldAny higher-layer output that depended on the now-insufficient substrate.
  9. Fail-closedThis entire walkthrough is a fail-closed path by definition — insufficient substrate routes to degraded/local mode or silence.
  10. RecordedThe substrate-state transition is written to the audit ledger.
  11. Public non-claimNot certified emergency hardware, not a guarantee of uptime.
8. NICOLE revocation / lease-expiry walkthroughNICOLE
  1. TriggerA previously granted access lease reaches its epoch/expiry, or the subject actively revokes consent.
  2. First sensedNICOLE's own epoch clock and the revocation-flag state, not a physical sensor.
  3. Truth authorityNot applicable — this walkthrough is entirely inside Custody Authority.
  4. Consequence interpretationNot applicable — no domain model runs during a revocation event.
  5. TSARONot invoked — revocation is a custody event, not a physical-admissibility event.
  6. NICOLE gateRe-evaluates role ∧ scope ∧ consent/lease ∧ epoch ∧ no revocation ∧ audit; the revoked/expired conjunct now fails.
  7. Receives outputNo one — any party who previously held access loses it at this point.
  8. WithheldAll previously permitted data for that lease, immediately.
  9. Fail-closedRevocation always wins — there is no override path once a lease is revoked or expired.
  10. RecordedThe revocation/expiry event itself is written to the immutable audit ledger.
  11. Public non-claimNot a certified privacy or regulatory-compliance product by itself.
9. Public reviewer / SSES proof-request walkthroughSSES
  1. TriggerA reviewer (professor, researcher, journalist) requests evidence for a claim made on the public site.
  2. First sensedNot a sensor event — the input is the specific claim being checked, e.g. an evidence-page row.
  3. Truth authorityNot directly invoked; SSES checks the evidence trail behind an already-computed result, not raw sensor truth.
  4. Consequence interpretationNot applicable — SSES governs presentation of an existing result, not a new domain computation.
  5. TSARONot invoked — no physical action is being taken.
  6. NICOLE gateConfirms the requested evidence is scoped to public/reviewer access, not individual-level data.
  7. Receives outputThe reviewer, via a Proof Library artifact, evidence-page row, or paper with an attached maturity label.
  8. WithheldProtected implementation constants, private repository contents, and any individual-level record.
  9. Fail-closedIf the claim cannot be traced to a labeled artifact, SSES withholds or downgrades the public statement rather than asserting it anyway.
  10. RecordedThe publication decision itself is documented in the site's own claim-boundary and non-claims language.
  11. Public non-claimIs not itself a peer-review process, not a regulatory certification.
10. Sovereign Root pre-authorized emergency doctrine walkthroughSovereign Root · NICOLE
  1. TriggerA user has, in advance, configured a bounded emergency doctrine — for example, permitting a minimized SOS packet to reach a specific BFB responder scope automatically if a defined distress state is confirmed, without an in-the-moment approval.
  2. First sensedNot a sensor event — the input is the user's own pre-authorization record, held under Sovereign Root policy.
  3. Truth authorityNot directly invoked at configuration time; applies later when an actual distress state is evaluated.
  4. Consequence interpretationNot applicable at configuration time.
  5. TSARONot invoked at configuration time; still evaluates the later distress state's admissibility exactly as it would without any pre-authorization on file.
  6. NICOLE gateMechanically enforces the pre-authorized doctrine's exact scope, purpose, and role boundary at the moment a real event occurs — it cannot be exceeded by that doctrine, only satisfied by it.
  7. Receives outputWhatever role and scope the user's doctrine named in advance — never a broader one just because the request is time-sensitive.
  8. WithheldAnything outside the pre-authorized scope; a pre-authorization for BFB packet release does not pre-authorize a TAB audio session, medical release, or any other separate NICOLE-gated action.
  9. Fail-closedAn ambiguous, expired, or revoked pre-authorization is treated as no pre-authorization at all — the system falls back to requiring a fresh authorization event, not to assuming consent.
  10. RecordedThe doctrine's configuration, and every time it is actually invoked, are both written to the audit ledger.
  11. Public non-claimPre-authorization does not override physical law, applicable law, another person's rights, or safety boundaries, and is not a substitute for consent law.

Authority matrix

One row per component, one column per capability. "Audited by" names who logs the decision — in every case, this ends at NICOLE Protocol's ledger, SSES's publication discipline, or both. Below 768px this becomes a stacked card per component instead of a squeezed table.

ComponentAuthority typeReads state/truthMakes a bounded decisionWhere may its output appear?Fail-closed defaultAudited by
Sovereign RootConstitutionalNo — no sensorsYes — consent gateGoverns whether anything else may releaseYesSelf (constitutional record)
CivOSSubstrateYes — infrastructure telemetryYes — degraded-mode selectionNoYesNICOLE Protocol
W-XTruthYesYes — admissibilityNoYesNICOLE Protocol
TSAROAdmissibilityYes — transient onlyYes — admit / contract / fail-closedNever — release is NICOLE Protocol's jobYes, by defaultNICOLE Protocol
SSIConsequenceYesYes — pressure proxyOnly via NICOLE Protocol-cleared scopeYesNICOLE Protocol
WX-AgConsequenceYesYes — field-burden proxyOnly via NICOLE Protocol-cleared scopeYesNICOLE Protocol
NICOLE ProtocolCustodyYes — custody metadataYes — grant / deny / expireGrants, denies, narrows, expires, or revokes scoped operational release. Does not replace the domain interface; a first-party local display is not automatically a third-party disclosure.Yes, deny by defaultSelf (audit ledger); publication scope reviewed by SSES
SOSCoordinationYesYes — minimizes state and routes it to the user interface, and optionally to BFBFirst-party: user's own phone/tablet/wearable interface. Responder branch (optional): a separate minimized packet enters BFB only after TSARO admissibility and NICOLE Protocol release authorization. User presentation is not responder disclosure.YesNICOLE Protocol
BFB (incl. TAB feature)Coordination interface under SOSNo — relay/display onlyNo — cannot independently validate physical truth or admissibility; cannot independently authorize release or audio accessDisplays only the responder-scoped incident packet authorized for the active incident. Not the civilian user interface. TAB is an additional, separately authorized, time-bounded feature.Yes — display only currently authorized bounded state; no TAB connection without separate approvalAccess governor: NICOLE Protocol · Physical governor: TSARO
SSESEvidence-adjudication perimeterYes — aggregate onlyYes — publish / withhold / labelGoverns public-facing artifacts and claim support only. Not ordinary local user presentation or operational BFB delivery.Yes, withhold by defaultSelf; only publishes NICOLE Protocol-cleared input
Constitutional
Component
Sovereign Root
Reads state/truth
No — no sensors
Makes a bounded decision
Yes — consent gate
Where may its output appear?
Governs whether anything else may release
Fail-closed default
Yes
Audited by
Self (constitutional record)
Substrate
Component
CivOS
Reads state/truth
Yes — infrastructure telemetry
Makes a bounded decision
Yes — degraded-mode selection
Where may its output appear?
No public-facing output of its own
Fail-closed default
Yes
Audited by
NICOLE Protocol
Truth
Component
W-X
Reads state/truth
Yes
Makes a bounded decision
Yes — admissibility
Where may its output appear?
No public-facing output of its own
Fail-closed default
Yes
Audited by
NICOLE Protocol
Admissibility
Component
TSARO
Reads state/truth
Yes — transient only
Makes a bounded decision
Yes — admit / contract / fail-closed
Where may its output appear?
Never releases anything itself — release is NICOLE Protocol's job
Fail-closed default
Yes, by default
Audited by
NICOLE Protocol
Consequence
Component
SSI
Reads state/truth
Yes
Makes a bounded decision
Yes — pressure proxy
Where may its output appear?
Role-scoped human interface only, via NICOLE Protocol-cleared scope
Fail-closed default
Yes
Audited by
NICOLE Protocol
Consequence
Component
WX-Ag
Reads state/truth
Yes
Makes a bounded decision
Yes — field-burden proxy
Where may its output appear?
Role-scoped human interface only, via NICOLE Protocol-cleared scope
Fail-closed default
Yes
Audited by
NICOLE Protocol
Custody
Component
NICOLE Protocol
Reads state/truth
Yes — custody metadata
Makes a bounded decision
Yes — grant / deny / expire
Where may its output appear?
NICOLE Protocol grants, denies, narrows, expires, or revokes scoped operational release. It does not replace the user's domain interface and does not mean every first-party display is a third-party disclosure.
Fail-closed default
Yes, deny by default
Audited by
Self (audit ledger); publication scope reviewed by SSES
Coordination
Component
SOS
Reads state/truth
Yes
Makes a bounded decision
Yes — minimizes state and routes it to the user interface, and optionally to BFB
Where may its output appear?
First-party interface: bounded safety state may appear directly on the user's own phone, tablet, or supported wearable-linked interface. Responder branch: a separate minimized packet may enter BFB only after applicable TSARO admissibility and NICOLE Protocol release authorization. User presentation is not responder disclosure.
Fail-closed default
Yes
Audited by
NICOLE Protocol
Coordination interface under SOS
Component
BFB (incl. TAB feature)
Reads state/truth
No — relay/display only
Makes a bounded decision
No — cannot independently validate physical truth or admissibility; cannot independently authorize release or audio access
Where may its output appear?
BFB displays only the responder-scoped incident packet authorized for the active incident. It is not the civilian user interface. TAB remains an additional, separately authorized, time-bounded BFB feature.
Fail-closed default
Yes — display only currently authorized bounded state; no TAB connection without separate approval
Audited by
Access governor: NICOLE Protocol · Physical governor: TSARO
Evidence-Adjudication Perimeter
Component
SSES
Reads state/truth
Yes — aggregate only
Makes a bounded decision
Yes — publish / withhold / label
Where may its output appear?
SSES governs public-facing artifacts and claim support. It does not govern ordinary local user presentation or operational BFB delivery.
Fail-closed default
Yes, withhold by default
Audited by
Self; only publishes NICOLE Protocol-cleared input

TAB is intentionally represented as a governed BFB feature — a nested capability with its own consent, connection, session, and audit rules — rather than as a separate authority or standalone component with its own row.

Data classification legend

Every field named in a chapter's "data classification touched" row is one of these 13 classes. The last two exist specifically so this page can say, in the open, that some material is deliberately withheld rather than pretend no such material exists.

1
Public NarrativeExplanatory and marketing-adjacent copy, always subject to SSES claim discipline.
2
Public Proof-BoundedSSES-cleared simulation output shown with a maturity label and non-claims.
3
Aggregate StatisticalNon-identifying summary statistics across many runs or many subjects.
4
Environmental Ground TruthW-X sensor and mesh state, with freshness and admissibility markers.
5
Agricultural Field StateWX-Ag crop, soil, and water-balance state for a specific field zone.
6
Structural Load StateSSI biomechanical proxy state — sensitive, biometric-adjacent.
7
Civilian Distress StateSOS's local incident state before any minimization or release.
8
Responder-Scoped PacketThe minimized, BFB-bounded handoff data a responder actually sees.
9
Consent-Gated AudioA TAB audio session's state — always time-boxed and lease-scoped.
10
Custody / Lease MetadataNICOLE Protocol's own role, scope, consent, and epoch records.
11
Audit Ledger EntryAn immutable record of a decision, granted or denied.
12
Protected Implementation ConstantInternal thresholds and tuning values. Named here as a class that exists — never shown.
13
Restricted / Private Repository MaterialSource code and internal specifications. Referenced only through reviewer-access.html, never linked directly in public.

Maturity and evidence classes — two separate scales

Every major capability on this page carries two separate maturity statements — evidence maturity (how the claim is known) and operational maturity (how far the capability itself has been built). No single badge conflates them: a deployed webpage is a Production-Deployed Interface, which does not imply the underlying system is field deployed, and an academic capstone review is Academic Capstone Reviewed, which is not scientific or operational validation.

Evidence maturity scale

1
Architecture DoctrineConceptual framing only — no simulation exists yet.
2
Provisional / R&DAn early-stage concept drawn from a source specification, not built.
3
Simulation PrototypeRunning in a bounded simulation, with no external validation yet.
4
Public Simulation / ReceiptVisible, bounded run output live on this site right now.
5
Internal ValidationTested by the team, not yet reviewed by an outside evaluator.
6
Academic Capstone ReviewedReviewed in an academic capstone track — not scientific or operational validation.
7
Public Technical ManuscriptAppears in a public paper or manuscript — not peer-reviewed unless separately stated.
8
Public Preprint / Working PaperPublic but not yet externally reviewed.
9
Submitted for External ReviewUnder review by an outside venue or evaluator.
10
Peer-Reviewed PublicationAccepted through external peer review.
11
Field Validation / Externally ValidatedValidated against real-world outcomes by an external party.

Operational maturity scale

1
ConceptNamed and framed, not yet specified.
2
Engineering SpecificationDesigned in detail, not yet simulated or built.
3
PrototypeA working internal implementation exists.
4
Public Interactive SurfaceA public, interactive simulation or workbench is live on this site.
5
Internally ImplementedRunning internally beyond the public surface.
6
Pilot / Field-PilotedUsed in a real bounded pilot outside of simulation.
7
Production-Deployed InterfaceThe public interface is live in the deployed site today — this does not imply the underlying system is field deployed.

Architecture-to-simulation bridge

Each operational domain has a public simulation or workbench. Cross-cutting authorities such as CivOS, TSARO, and NICOLE Protocol are demonstrated inside those domain execution paths rather than necessarily having separate standalone simulation pages — this is the bridge from the map to the running system, before any result is turned into a public evidence artifact.

Architecture-to-proof bridge

The Proof Library connects each architecture component to the public-safe simulation or workbench behavior in which it is exercised, the resulting receipt or evidence artifact, the sequence of authority decisions, and the bounded claim that the artifact may support. Architecture ≠ execution surface ≠ Proof Library — the three surfaces are connected but perform different functions. This is the bridge from a running result to what SSES has cleared to say about it publicly.

Public non-claims

These twenty-three statements are not fine print. They are exactly as central to the architecture as the components above — every chapter's boundary field traces back to one of these.

  • LAKANA does not guarantee a rescue, delivery, or emergency-response outcome.
  • LAKANA is not a replacement for 911, emergency managers, or professional responders.
  • TSARO is not "unbreakable" — it is fail-closed under tested conditions, not immune to failure.
  • No LAKANA claim describes an outcome as "mathematically impossible" — only "not observed under tested conditions."
  • SSI is not medical diagnosis, return-to-play authority, or clinical validation.
  • SSI makes no sex-superiority, performance-ranking, or fitness-for-duty determination.
  • WX-Ag gives no yield guarantee, farm directive, or insurance/lender score.
  • W-X does not replace or override official radar, Mesonet, or NWS warnings.
  • NICOLE Protocol is not a certified privacy or regulatory-compliance product by itself.
  • CivOS is not certified emergency hardware and carries no uptime guarantee.
  • BFB is not a dispatch system and provides no continuous location tracking.
  • TAB is not an always-on microphone and performs no passive audio surveillance or voice-biometric identification.
  • No LAKANA component performs biometric identification of any individual.
  • This page discloses no protected implementation constants, private keys, tokens, or internal thresholds.
  • This page does not publish or link directly to private repository source code.
  • Nothing here is represented as formally, mathematically proven safe — the equations describe bounded engineering proxies, not proofs.
  • Simulation and receipt evidence shown here is architecture-level and bounded; it is not field-deployment validation.
  • Publication in the SSES is not itself a peer-review process or a regulatory certification.
  • No LAKANA authority claims to eliminate uncertainty — TSARO contracts safe action under uncertainty; it does not remove it.
  • Battery and energy figures on this page are engineering targets or labeled stochastic simulations — not measured fleet performance.
  • No compatibility or compliance with NIMS, FEMA, ICS, or any dispatch environment is claimed.
  • No threshold-custody deployment is claimed; threshold post-quantum operation remains a research track requiring external analysis.
  • Where a source specification described a capability not yet built or tested — for example predictive biometric wearables, deceptive-shutdown countermeasures, or blockchain evidence ledgers — this page labels it Provisional / R&D rather than presenting it as current.

Architecture decision records

The load-bearing public design decisions, each with its reason and consequence, so a reviewer can distinguish a deliberate boundary from an accident. No protected implementation detail appears in any record.

ADR-001 — Separate survival from domain interpretation

Decision: CivOS owns substrate survival; domain lanes own interpretation. Reason: a system that both keeps itself alive and decides what data means can silently fake capability. Consequence: every lane consumes an explicit CivOS capability state. Related: CivOS, Energy Discipline.

ADR-002 — Separate truth from consequence

Decision: W-X establishes environmental truth; SSI and WX-Ag interpret consequence. Reason: blending them forces the truth layer into directive claims. Consequence: consequence is withheld when truth is inadmissible. Related: W-X, WX-Ag, SSI.

ADR-003 — TSARO owns admissibility, not custody

Decision: TSARO decides physical admissibility and never releases anything itself. Reason: safety and custody have different failure modes. Consequence: a "safe" action cannot bypass access control. Related: TSARO, NICOLE Protocol.

ADR-004 — NICOLE Protocol governs operational release

Decision: all protected, personal, custody-sensitive and role-scoped release passes NICOLE Protocol. Reason: release needs an accountable, revocable record. Consequence: grants and denials are both audit events. Related: NICOLE Protocol.

ADR-005 — SSES is a public evidence perimeter, not an operational gate

Decision: SSES adjudicates only material being published. Reason: operational outputs and public claims have different risks. Consequence: a responder packet never passes through SSES. Related: SSES.

ADR-006 — BFB contains TAB

Decision: TAB is a governed feature nested inside BFB, never a peer system. Reason: audio-request capability only makes sense inside an authorized incident workspace. Consequence: TAB has no standalone chapter, fragment, or authority row. Related: BFB, TAB.

ADR-007 — BFB access does not authorize TAB

Decision: a TAB session is a separate, additional, time-boxed NICOLE Protocol lease. Reason: incident visibility and live audio are different intrusions. Consequence: BFB access is not TAB authorization — ever. Related: TAB flow.

ADR-008 — No false delivery state

Decision: failed or unavailable transport yields a visible preserved-locally state. Reason: a false "delivered" claim in an emergency is worse than an honest failure. Consequence: Local-Preserve is never presented as delivery. Related: CivOS modes, degraded-state matrix.

ADR-009 — Energy capability must be explicit

Decision: CivOS exposes a formal operating mode instead of best-effort behavior. Reason: capability that silently degrades produces false trust. Consequence: reduced capability is always user-visible. Related: Energy Discipline.

ADR-010 — Battery thresholds remain protected policy parameters

Decision: mode-transition thresholds are published as abstract parameters, never as values. Reason: exact constants are tuning-sensitive implementation detail. Consequence: the public page shows π_critical form, not numbers. Related: Energy contract, disclosure boundary.

ADR-011 — Standardized cryptographic primitives are distinct from threshold research

Decision: ML-KEM/ML-DSA usage, LAKANA integration, and threshold research are three separately labeled classes. Reason: a standardized primitive does not validate an integration. Consequence: no threshold deployment claim appears without its research label. Related: NICOLE custody.

ADR-012 — Vehicle-related transport concepts excluded from the public Architecture page

Decision: vehicle-mesh and related transport-implementation concepts are excluded from this page entirely. Reason: they are security-sensitive, patent-sensitive, and not part of the public architecture contract. Consequence: CivOS transport appears only as an abstract state class. Related: public transport abstraction.

Reviewer checklist

What a reviewer can verify from this page
  • Canonical architecture and component boundaries
  • Authority ownership and the seven operational authority types
  • Public state classes and refusal states
  • Human role/device boundaries — what each role sees and does not see
  • Formal public equations with dictionaries and protected boundaries
  • Simulation classifications and separated evidence/operational maturity
  • Public non-claims and the disclosure boundary
  • Links to every public live surface
What this page cannot verify by itself
  • Production runtime internals or cryptographic implementation security
  • Formal verification or FIPS validation
  • NIMS/ICS compatibility or certified dispatch integration
  • Medical validity or emergency effectiveness
  • Agronomic field validity
  • Battery performance on real devices, uptime, or delivery probability
  • Forensic erasure
  • Real-world outcome improvements

Versioned architecture snapshot and citation

The exact version of this Architecture page being reviewed. Snapshot metadata is generated locally at build time into assets/architecture-snapshot.json — no remote service is involved — and shown here when available.

Architecture version
A2 — see assets/architecture-snapshot.json
Git commit
recorded at build time in assets/architecture-snapshot.json
Architecture HTML SHA-256
recorded at build time in assets/architecture-snapshot.json
Build date
recorded at build time in assets/architecture-snapshot.json

LAKANA Sovereign Systems LLC. "LAKANA Sovereign Systems Architecture." Architecture snapshot [short hash], dated [ISO date], lakana.systems/architecture.html.