Control Plane
Identity, institutional membership, role, tenant scope, authority, policy intent, data boundary, provider route, runtime contract, and activation decisions.
One shared core for institutional and capability operations
The model-native trust layer that governs intent before execution, constrains runtime behavior, captures evidence after execution, qualifies bounded proof, and keeps commercial eligibility downstream from authority and trust.
Five operating planes
KSAI avoids the common failure of mixing configuration, execution, evidence, public trust, and billing into one dashboard. The interface exposes only the plane and actions appropriate to the user’s role, scope, and current gate.
Identity, institutional membership, role, tenant scope, authority, policy intent, data boundary, provider route, runtime contract, and activation decisions.
Governed model, agent, tool, workflow, provider, cloud, private-runtime, timeout, retry, idempotency, isolation, and recovery behavior.
Minimum approved evidence, event lineage, redaction, audit references, proof inputs, retention, recovery records, and dispute support.
Proof Receipt, verifier projection, AI Passport, Trust Badge, SVER qualification, status, expiry, revocation, and bounded public claims.
Plan entitlement, activation authorization, qualified outcome, value claim, usage, cost, margin, billing eligibility, settlement, and dispute boundaries.
Canonical runtime laws
Disabled actions explain the missing condition. Error messages state what failed, what is safe to disclose, who can resolve it, and whether retry, remediation, review, or escalation is the valid next step.
Runtime law 01
Authentication alone does not create institutional membership, role, tenant scope, or runtime authority.
Runtime law 02
The model, provider, tool, data boundary, route, policy, timeout, retry, evidence, and recovery conditions must be locked before execution.
Runtime law 03
A successful technical response is not sufficient to issue a Proof Receipt or public trust projection.
Runtime law 04
Verification and technical success do not automatically establish a qualified outcome or commercial value.
Runtime law 05
Commercial activity remains blocked until the required proof, contract, entitlement, and authorization conditions are satisfied.
Runtime law 06
Tenant evidence, secrets, payloads, authority, and private operating details never move into public interfaces by default.
Choose the correct operating surface
Use the Institutional Governance Track to define scope, readiness, policy, trust routes, activation, and recurring governance operations.
Open institutional trackUse Capability Economy to package models, agents, tools, providers, passports, verification, and controlled distribution.
Open capability trackUse Trust surfaces to inspect bounded status and signed public projections without entering protected runtime or evidence planes.
Open trust surfacesOne core · Explicit gates · Safe disclosure