AMOF

Runtime Authority for governed AI execution

Models are workers. Runtime is authority.

AMOF owns Sessions, policy, Evidence, and stop authority so AI work can run in production without treating chat as the system of record.

Predator Operate workspace with an active Session, Objective, confirmed target, and completed run
Predator — active Session under Runtime Authority

The problem

Models propose. Production needs authority.

Useful AI output is not enough. Executions need scope, approvals, identity, and Evidence — or operators inherit unreliable chat claims.

Proposal is cheap

Workers can draft plans and patches quickly. That does not make them trustworthy executors.

Prompts are not gates

Asking a model to be careful cannot revoke a write grant or prove a path stayed in scope.

Evidence must be durable

If it is not recorded, it is not runtime truth. Scrollback is not an audit trail.

Governed execution flow from model proposal through runtime decision, scope, operator gate, and Evidence
Proposal is not authority — Runtime Authority closes the loop with Evidence

Runtime Authority

The control plane for AI work

Runtime Authority plans the Session, compiles context, delegates to Workers, enforces policy, collects Evidence, and controls release readiness.

Runtime Authority lifecycle: Intake, Decision, Bounded run, Evidence, Review
Intake → decision → bounded execution → Evidence → review / promote
Intake
Decision
Bounded run
Evidence
Review

Deep dive: Runtime Authority architecture — product concept page, not a personal blog.

Predator

Private operator cockpit

Predator is the primary operator experience on AMOF Runtime Authority. Private product. Not in the public OSS distribution. Cloud-dev release candidate under operator gate — not a public GA hostname.

Human-gated Decisions

See what is waiting on the operator before mutation is allowed.

Runs and Results

Inspect completed and blocked Runs with durable outcome records.

Evidence

Browse secret-safe run Evidence instead of trusting chat summaries.

Workforce policy

Select replaceable Workers under policy ceilings. Ladders never grant authority.

Governance and trust

Secure by governance — scopes, approvals, Evidence

Trust comes from what the runtime can enforce, inspect, and stop.

Governance diagram connecting writable scopes, approvals, Evidence, and runtime identity
Scope, approval, and Evidence must connect — or trust is theatre

Writable scopes

Bounded paths and capability modes. Over-bound work fails closed at dispatch.

Approvals

Write-scope and elevated mutation require an operator decision before bind.

Runtime identity

Sessions carry authority. Ended Sessions do not retain write rights.

Replay and audit

Receipts and run records make outcomes inspectable after the fact.

Architecture

Workers propose. Runtime decides what is true.

Models and tools are replaceable Workers. Runtime Authority is the system of record for Objectives, Sessions, policy, and Evidence.

Comparison of Runtime Authority ownership versus replaceable Workers
Runtime Authority owns truth and policy. Workers stay replaceable.

Models as Workers

GPT, Claude, Grok, and tools execute delegated work — they do not own grants.

Runtime as authority

Policy, stop, and Evidence stay outside the model.

Governed loops

Explicit stop conditions. Human gates where mutation matters.

Product proof

Named surfaces. Honest maturity.

Public OSS — AMOF 3.3

Write-Scope Authority (Apache-2.0). Installable local governed runtime. Does not ship Predator or private cloud topology.

Release notes

Predator — RC

Private operator cockpit on Runtime Authority. Cloud-dev release candidate under operator gate. Not publicly announced.

Evidence-first

Receipts, run records, and runtime logs are first-class. Missing provider cost stays unknown — never fabricated.

Next step

See the operator cockpit. Read the architecture.

Predator for operators. Public OSS for Write-Scope Authority.