AMOF

Engineering Trust in AI

Models are workers. Runtime is authority.

Governed, evidence-first AI infrastructure. Workers propose; the runtime owns grants, receipts, and stop authority.

Core principle

Models propose. The runtime decides what is true.

Cognition workers are replaceable. Sessions, scopes, approvals, bindings, and MutationReceipts live in Runtime Authority — not in chat output.

Runtime Authority

Write-Scope Authority — propose → inspect → approve → bind → enforce → audit.

Production infrastructure for AI operations: finite TTL grants, path enforcement, fail-closed bounds, and inspectable evidence. Not another prompt framework.

Predator

Private operator cockpit on Runtime Authority

Predator is a private operator product built on AMOF Runtime Authority. Not in the open-source distribution. Not publicly announced. Cloud-dev release candidate under operator gate — not a public GA hostname.

Predator Operate workspace showing Golden Flow: mission, target, and run under Runtime Authority
Golden Flow — intake through dispatch to evidence under operator supervision. Autopilot pauses at write-scope approval.

Human-gated scope

Decisions show what is waiting on the operator. Mutation requires a human decision — workers propose; operators decide.

Historical read-only

Ended pins never restore write authority. Historical sessions are inspectable and explicitly read-only.

Workforce ladders

Role ladders select replaceable model workers under runtime policy. Ladders never grant mutation authority.

Cost & provenance

Runs record cost and model provenance. Missing provider cost stays unknown — never fabricated as zero.

Predator Decisions workspace for operator approvals
Decisions — waiting-on-operator surface
Predator historical session marked HISTORICAL READ_ONLY
Historical sessions — read-only authority
Predator Mission Result after a supervised Golden Flow run
Mission Result — governed run outcome
Predator Evidence workspace for secret-safe run evidence
Evidence — receipts and run paths
Predator Workforce ladders for planner, executor, and verifier roles
Workforce — model ladders under policy
Predator Decisions after operator resolution of a waiting row
Decisions — post-resolution state
Private / not announced Governance model Public AMOF on GitHub

Architecture · Evidence · Governance

Secure by governance — scopes, approvals, and evidence.

Trust comes from what the runtime can enforce, inspect, and stop — not from asking a model to be careful.

Scopes & workspaces
Workers operate inside explicit scopes, workspaces, and capability modes with path enforcement.
Approvals
Write-scope and elevated mutation require operator decision before bind and enforce.
Receipts
MutationReceipts and run records prove whether execution stayed inside the grant.
Fail-closed bounds
Over-bound or invalid work stops dispatch instead of silently truncating into execution.
Stop / revoke
Operators cancel autopilot and revoke grants. Ended sessions clear write authority.
Public / private boundary
OSS ships Write-Scope Authority locally. Predator consumes the same contracts as a private cockpit.
Model workers
Runtime Authority
Scopes · approvals · receipts
Evidence

Release status

Honest maturity — named surfaces only.

Public OSS

AMOF 3.3 — Write-Scope Authority

Apache-2.0. Installable local-first CLI and governed runtime. Production-ready Write-Scope Authority for local OSS use (v3.3.0).

Release notes →

Private product

Predator — release candidate

Private operator cockpit on Runtime Authority. Cloud-dev RC under operator gate. Not a public hostname claim. Not announced.

Cockpit overview →

AMOF

Get started

Install the public CLI. Govern mutations with approvals and receipts.

Docs live on public GitHub: marekhotshot/amof · Write-Scope Authority · Execution chain