The Silicon Sentry of Verifiable Law & Intent Gating
The Gatekeeper is the inward-facing constitutional checkpoint operating within the onePOI.online System of Orchestration (SoO). Positioned as the non-bypassable admission gate to the execution plane, the Gatekeeper is completely decoupled from external network routing, cloud APIs, and physical peripheral drivers.
Its single, precise operational mandate is to hold all incoming Actuator DAGs in a strict fail-closed lock until it intercepts, decrypts, and cryptographically validates a signed Lawful Warrant (PERMIT) issued by the DRAGON Adjudication Engine. The Gatekeeper is the platform’s constitutional magistrate, ensuring that no technical instruction can materialize into kinetic action without unchallengeable legal and regulatory authority.
Engineered for Institutional Margins.
Adopted for Human Sovereignty.
Every capability across the Salient Innovation Set delivers an immediate, symmetrical return: radical margin recovery for the enterprise tenant, paired with frictionless dignity and absolute cryptographic safety for the citizen.
How the Tenant Expands Margins
Transforming operating models from defensive cost centres into agile, shared revenue engines through multi-tenant pooling and mathematical compliance.
-
CapEx Pooling & No Single-Tenant Hardware
POI Appliances run white-label on co-funded premises. Reach 50 commercial catchments without funding 50 proprietary branch builds.
-
Zero Interchange & Flat-Fee Clearing
Instant Account-to-Account rails (SEPA Instant / PayShap) bypass 1.5–3.5% card scheme tolls with predictable, flat sub-cent clearing fees.
-
Compliance by Construction
Agreement DAGs enforce statutory mandates at wire speed; non-compliant states cannot execute, eliminating retrospective audit penalties.
-
Accelerated Partner Onboarding
Pre-verified BIAN and ArchiMate capability components compress multi-firm integration cycles from quarters to days.
Why the Customer Loves Using It
Delivering sovereign dignity and verifiable security where users never surrender control over their identity, consent, or funds.
-
Nothing Stored to Steal
Credentials remain in the user's oneWallet. A breach of a merchant's server reveals zero identity records, protecting citizens completely.
-
One Pattern, Everywhere
The same intuitive tap-and-confirm interaction works seamlessly at a high-street kiosk, transit hub, EV charger, or smartphone.
-
Delegated Authority, Never Escalated
Autonomous AI agents carry single-use, bounded warrants; an agent checking information cannot escalate its authority to transfer money.
-
Payments That Do Not Fail
When a payment network degrades, the transaction reroutes with authentication preserved – zero declines, zero repeated entries.
Gatekeeper Runtime Manifest
Constitutional Admission Magistrate
Core Operational Capabilities
Gatekeeper secures the boundary between judicial intent and physical actuation across the Salient FinTech Innovation Set.
1. Cryptographic Warrant Interception & Attestation
Operates inside hardware-isolated Trusted Execution Environments (TEEs), intercepting execution requests and validating \(O(1)\) constant-time cryptographic signatures against the platform's root-of-trust before releasing locks.
2. Intent-Aware Workload Scheduling
Manages the queuing and release of Actuator DAGs, resolving inter-stanza dependencies, late-binding Pulumi outputs, and bitemporal constraints across Valid-Time (\(V_t\)) and Transaction-Time (\(T_t\)) axes.
3. Intent-Frame Context Hydration
Extracts the Policy Hash (\(\mathcal{PH}\)) embedded within the warrant and binds runtime variables to version-pinned TopHAT constraints, preventing ultra vires parameter injection or execution drift.
4. Deontic Boundary Enforcement (\(\mathbf{F} \succ \mathbf{O} \succ \mathbf{P}\))
Acts as the mechanical circuit breaker for deontic logic governance. If an instruction trips a Prohibition (\(\mathbf{F}\)), Gatekeeper executes an instantaneous Structural VETO, paralyzing threads before state changes occur.
The Subsystem Triad of the System of Orchestration (SoO)
Within the SoO, execution is decomposed across three distinct capability blocks with rigid mathematical boundaries, preventing execution logic from ever bypassing or degrading constitutional policy.
The Constitutional Magistrate
The inward-facing security boundary and constitutional checkstop. Intercepts inbound Actuator DAGs, holds them in strict HALT until a signed DRAGON PERMIT is validated, and hydrates the runtime Intent Frame.
- Admission Control: Holds DAGs in HALT until DRAGON PERMIT validation.
- Intent Hydration: Binds runtime to parent Agreement DAG Intent Frame.
- State Validation: Refuses tokens for unmapped topological paths.
The Macro-Orchestration Core
The middle-out macro-orchestration hub. Translates authorised business intent into technical runbooks, decomposing workflows into Stanzas and Strophes while managing Contrary-to-Duty (CTD) Sagas.
- Grammar Decomposition: Decomposes playbooks into Stanzas and Strophes.
- Saga Management: Manages durable sagas and executes automatic CTD reversals.
- State Checkpointing: Commits state before and after every Stanza transition.
The Kinetic Dispatcher
The outward-facing routing and kinetic dispatch engine. Blind to legal reasoning, its mandate is operational: fast, reliable movement of data and commands across the geo-distributed infrastructure grid.
- Omni Dispatch: Dispatches idempotent instructions to PBCs and POI appliances.
- Idempotent Action: Guarantees safe retries during network partitions.
- Telemetry Harvesting: Funnels execution Glyphs into MAESTRO for auditability.
The 7-Step Lockstep Execution Handshake
This triad operates through a strict, non-repudiable 7-step handshake that guarantees Substantiated Integrity:
1. Intercept & Validate: The Gatekeeper catches the execution request, halts it, and waits for the DRAGON warrant.
2. Bind & Unlock: Upon warrant validation, the Gatekeeper hydrates the token and passes it to the Conductor.
3. Orchestrate: The Conductor manages the workflow sequencing and saga integrity.
4. Route & Actuate: Flow360 handles the kinetic dispatch, navigating the network to hit the physical edge endpoint.
5. Attest: Flow360 returns the signed evidence of the action (the Glyph), which the Gatekeeper seals into a Lawful Act Hyperedge (LAHE).
6. Commit: The LAHE is written to the immutable bitemporal ledger, closing the transaction loop.
Mitigating Core Failure Modes Across the Grid
By combining kernel-level eBPF filters, hardware attestation, and fail-closed state machines, Gatekeeper and the SoO triad defeat critical distributed attack vectors.
OWASP LLM06 (Excessive Agency)
Zero Executive Agency
AI models in the System of Intelligence have zero executive authority. They can only formulate non-binding Proposed Intent claims. Flow360 is physically blocked from executing unapproved calls via eBPF/XDP kernel hooks, which remain closed until Gatekeeper validates an authoritative PERMIT signed by DRAGON.
OWASP LLM03 (Supply Chain Integrity)
cATO & Dynamic PBOM
Continuous Authority to Operate (cATO) tracks dependencies via the PBOM (SBOM/HBOM/DBOM/MBOM). If a vulnerability is announced, the Event Mesh alerts Gatekeeper, which instantly invalidates the asset in cache, severs communication rails in under 100 microseconds, and refuses execution.
Network Degradation & WAN Blackout
Constitutional Island Mode
During network partition, POI Appliances enter Constitutional Island Mode. Edge orchestrators evaluate cached local Agreement DAG rules. If local evidence is insufficient to clear deontic constraints, Gatekeeper refuses execution tokens, and Flow360 blocks mechatronic relays, locking assets in a fail-closed state.
Catastrophic Tamper & Hardware Intrusion
Dynamic Bus-Impedance Defense
Motherboard trace monitoring detects physical probe attachments or voltage glitches in microseconds. Flow360 immediately triggers hardware zeroization relays (clearing SRAM keys) and mechanically locks peripheral cash cassettes while the Gatekeeper writes the terminal event receipt.
Deep Technical: Hardware-Isolated Coexistence within MTCCF & Silicon Apartments
Deep Technical: Hardware-Isolated Coexistence within MTCCF & Silicon Apartments
Under the Multi-Tenant Confidential Computing Framework (MTCCF), the memory footprints of the validation plane (Gatekeeper) and the execution routing plane (Flow360) are entirely segregated at the processor level.
Through strict page-table partitioning, core-exclusion policies, and UCIe 2.0 enclave boundaries (Silicon Apartments), the system ensures that even if Flow360's external, network-facing APIs are subjected to an advanced adversarial compromise, the attacker is physically blinded and blocked from "reaching back" into the Gatekeeper's memory space to leak root cryptographic keys or alter constitutional axioms.
Deep Technical: Short-Lived SPIFFE SVIDs & Token Gating
Deep Technical: Short-Lived SPIFFE SVIDs & Token Gating
The Gatekeeper integrates with SPIFFE/SPIRE to issue short-lived, cryptographically ephemeral SPIFFE Verifiable Identity Documents (SVIDs) for each individual stanza execution.
SVIDs expire within seconds of transaction completion, mitigating replay attacks and ensuring that compromised worker nodes cannot reuse expired authorisation tokens across unrelated transaction flows.
Deep Science: Deontic Logic Circuit Breaking & LAHE Generation
Deep Science: Deontic Logic Circuit Breaking & LAHE Generation
The Gatekeeper evaluates actions using a deterministic deontic decision function \(\mathcal{F}_{\text{deontic}}(a)\) where Prohibition Dominance (\(\mathbf{F} \succ \mathbf{O} \succ \mathbf{P}\)) is strictly enforced:
Upon verified execution return from Flow360, Gatekeeper binds the execution proof (\(\mathcal{G}\)) to the original DRAGON Lawful Warrant (\(\text{Warrant}_{\text{DRAGON}}\)) and Policy Hash (\(\mathcal{PH}\)), generating the immutable Lawful Act Hyperedge (LAHE):