Models reason.
Agents act.
Selected for the exact Work Order by capability and operating constraints.
- Task and complexity fit
- Quality and risk profile
- Latency and availability
- Cost per verified outcome
Reference architecture / 02
An AI software factory is a system of responsibilities. The architecture makes each responsibility visible so teams can decide what to build, buy, govern, verify, and operate.
Trust constrains every area. Learning closes the loop only through governed promotion. The model is replaceable; the control contract is not.
The control boundary
Models reason and agents act, but neither should own identity, permission, authoritative state, release policy, or the evidence used to judge its work. Those responsibilities belong to the factory around them.
Selected for the exact Work Order by capability and operating constraints.
Durable controls remain outside the model and apply to every provider, agent, and tool.
Every Attempt runs inside an explicit, observable, recoverable operating envelope.
Capability supply should evolve as better options emerge.
The operating record must survive every capability substitution.
Every Attempt returns attributable evidence. No producing system may promote its own result.
Capability map
Purpose describes why the area exists. Responsibilities and components describe what it owns. Decisions and failure modes reveal what must remain explicit.
Architecture area
Turn human goals into explicit, reviewable work before execution begins.
Expand areaCollapse areaRelationshipIntent supplies the frozen contract that Harness executes, Trust verifies, and Learning may propose changing only through governance.
Architecture area
Control the agent lifecycle outside the model so work survives sessions, failures, and handoffs.
Expand areaCollapse areaRelationshipHarness binds Intent, Capability, Model, and Trust into one exact Attempt and returns observations to Learning.
Architecture area
Make agents, skills, tools, context services, and interfaces versioned, discoverable, and governable.
Expand areaCollapse areaRelationshipCapability is selected from Intent, admitted by Trust, run by Harness, and may use one or more Models.
Architecture area
Abstract and route models by capability, quality, latency, cost, and policy.
Expand areaCollapse areaRelationshipModel executes inside the Harness, uses Capability and context, and remains constrained by Trust regardless of intelligence.
Architecture area
Keep authority outside the model and require evidence for consequential state transitions.
Expand areaCollapse areaRelationshipTrust constrains every other area and separates completion, verification, approval, and release.
Architecture area
Turn real outcomes, failures, cost, and reviewer decisions into bounded improvement proposals.
Expand areaCollapse areaRelationshipLearning consumes Trust-approved signals and returns proposed changes to Intent, Capability, Model, or policy—not directly to production.
Software factory concept
Continue