Human-gated scope
Decisions show what is waiting on the operator. Mutation requires a human decision — workers propose; operators decide.
AMOF
Models are workers. Runtime is authority.
Governed, evidence-first AI infrastructure. Workers propose; the runtime owns grants, receipts, and stop authority.
Models propose.
The runtime decides
what is true.
Core principle
Cognition workers are replaceable. Sessions, scopes, approvals, bindings, and MutationReceipts live in Runtime Authority — not in chat output.
Predator
Predator is a private operator product built on AMOF Runtime Authority. Not in the open-source distribution. Not publicly announced. Cloud-dev release candidate under operator gate — not a public GA hostname.
Decisions show what is waiting on the operator. Mutation requires a human decision — workers propose; operators decide.
Ended pins never restore write authority. Historical sessions are inspectable and explicitly read-only.
Role ladders select replaceable model workers under runtime policy. Ladders never grant mutation authority.
Runs record cost and model provenance. Missing provider cost stays unknown — never fabricated as zero.
Architecture · Evidence · Governance
Trust comes from what the runtime can enforce, inspect, and stop — not from asking a model to be careful.
Release status
Public OSS
Apache-2.0. Installable local-first CLI and governed runtime. Production-ready Write-Scope Authority for local OSS use (v3.3.0).
Release notes →Private product
Private operator cockpit on Runtime Authority. Cloud-dev RC under operator gate. Not a public hostname claim. Not announced.
Cockpit overview →AMOF
Install the public CLI. Govern mutations with approvals and receipts.
Docs live on public GitHub: marekhotshot/amof · Write-Scope Authority · Execution chain