Approach

Structure has architectural consequences. When a declaration settles a system's form before the system runs, the declaration can also settle the system's business rules, governance and use of models, knowledge and agents.

A composition carries an organisation's business rules the way it carries any other component, so the rules are settled before the system runs.

In a system composed on daedal, the rules go through three stages at build time and one in operation. The composition collects the components that hold the rules. Free Assembly proves the collected set is the same in any order of assembly. A rulebook step compiles the rules, checks them for coherence and stops the build if two conflict. The compiled rulebook records the identifier of its source declaration. In operation, the system applies the rules case by case and records against each result the rulebook that produced it.

An organisation's rules go through four stages. At build time the composition collects them, a rulebook step compiles them and stops the build on a conflict, and the compiled rulebook records the identifier of its source declaration. In operation, the system applies them case by case. BUILD TIME OPERATION 1Collect the componentsthat hold the rules 2Compile check coherence; aconflict stops the build 3Certify the rulebook recordsits source declaration 4Apply case by case; eachresult names its rulebook An organisation's rules go through four stages. At build time the composition collects them, a rulebook step compiles them and stops the build on a conflict, and the compiled rulebook records the identifier of its source declaration. In operation, the system applies them case by case. BUILD TIME 1Collect the components that hold the rules 2Compile check coherence; a conflictstops the build 3Certify the rulebook records its sourcedeclaration OPERATION 4Apply case by case; each result namesits rulebook
Specific before general
daedal delivers every rule to a rulebook step in a fixed order, deepest in the composition first. Specific rules sit deeper in the composition, so the rulebook step receives each specific rule first and applies it over the general rule it qualifies (lex specialis).
Experts keep the judgement
The organisation's experts write the rules and, by agreement with the team, remain responsible for what each rule means. The system treats the rules' contents as data.
Rules with an identity
A rule set carries an identity computed from its contents, so each result records the version of the rules that produced it. Changing a rule creates a new version of the system. A result computed against a superseded version reports that its version is superseded.
Accountability and reproducibility
Depending on its inputs, a figure may be reproducible from the declaration by anybody, only by the organisation, only by someone holding the same observation or by nobody. A person who signs off a proposed figure becomes accountable for it, and the figure keeps the reproducibility it had. One walk over the dependency graph stops at the signature and shows who is responsible for a value. A second walk crosses the signature and shows what the value rests on.

A declared system settles four questions in its structure: what is running, who authorised it, what the system knows and what the system can do. aidion keeps a standing record of each as the system runs.

Those four questions are the governance surfaces of an automated system: structural, authoritative, epistemic and executory. All four concern the agent. An agent is a program that pursues a goal. It holds state, decides the next step and acts only through the tools its builders grant it. A model is a function the agent calls. Governing Intelligent Systems sets out the four surfaces in full.

Declared reach
Each step declares which model outputs it uses unchanged and which it first checks against a source, a calculation or a person's review. The application's design therefore shows whether any unchecked model output reaches the organisation's clients.
Human review
We help teams set each agent's level of autonomy by the consequence of an error. The composition declares that level. The agent holds output below the organisation's confidence threshold for a person to review. Where a step leads to a signed opinion or a commitment of capital, a person reviews the step's output. Where a process requires separation of duties, the team builds the separation into the system's design.
Durable processes
Business processes run as workflows that record every step and resume from the last completed step after a failure.
Tested controls
We help teams test each check by introducing the fault it should detect. A team relies on a check once the check has reported that fault.
One process each
An organisation has three processes: its owners constitute it, its staff operate it and its owners account for that operation. Each system's composition names the one process the system serves. A system built for accounting observes the organisation's operation and records the obligations that operation creates. A system built for operation produces results and records how it derives each one.

Each model, each body of knowledge and each agent is a declared component, so a team can choose, review and version each one on its own.

Models

Each task runs on the smallest model that does that task well, so the organisation pays for the model the task needs. Besides large language models, AI includes embedding models for search and document similarity, classifiers for triage, time series models for market data and speech models for voice. We help teams choose a model for each task on precision and cost.

Business processes range from deterministic quantitative pipelines to agentic processes in which a model proposes the next action. Many processes combine the two.

The choice of model, the provisioning of infrastructure and the placing of human review each carry a cost and a value. We help teams weigh the engineering and the economics of each decision together.

Each model is a versioned component. In a workflow with fixed control flow, swapping one model for another leaves the process unchanged, so a team can compare the two models directly on the same inputs.

Knowledge

Every inference in the system uses knowledge the organisation's own experts have reviewed.

An automated system needs the tacit knowledge of an organisation's senior people written down. Those people take part in the work directly. A model can act as a structured interviewer, drawing out and formalising what practitioners find hard to state.

Each organisation has an ontology: the vocabulary of concepts it uses to classify opportunities, counterparties, risks, strategies and other objects in its domain. The ontology determines what context the system can retrieve for an inference. We help each engineering team identify and formalise the organisation's ontology while it builds the system.

An output stored as knowledge for later inferences meets a higher standard than an output delivered to a user. In each application a team builds on the engines, a person reviews each output below a confidence threshold before the application stores that output as knowledge. The application records which knowledge informed each output.

Agents

The organisation owns the program that makes each decision, and can inspect and version it.

Calling a model is an invocation. Adopting its output as a conclusion, or letting the output decide what happens next, is an inference. Governance controls apply to each inference.

Current usage treats the model as the agent. Under that usage, authority lies with a vendor's model, which the organisation has no means to own, version or show an auditor.

A system can call a model cheaply and often: extracting fields, classifying a form, drafting a paragraph, proposing a figure. An output checked against a source, re-derived by calculation or confirmed by a person is a proposal. An output adopted as it stands is a decision the model made. Such decisions reach clients in signed reports and regulators in filings.

The declaration states, for each step, whether it adopts an output as it stands, whether the output may trigger anything and what checks the output. From those declarations and the workflow's structure, anyone can list which model outputs reach the organisation's clients unchecked.

A step can also let a model's output select and call tools. The declaration sets each step's autonomy according to the consequence of an error.

A team frames, plans and runs each problem as separate steps, each a task with tight context.

Multi-agent systems take hierarchical, collaborative or competitive topologies. Hierarchical suits problems with a clear sequence. Collaborative suits problems that gain from several viewpoints. Competitive suits problems where quality outweighs efficiency. Each part of a system has the topology that suits its problem.

Automation usually starts in operations, with high-volume, well-defined processes where an error costs little. That work frees staff time and gives the organisation a track record of the system's performance. Automation then extends to the organisation's core work (the investment decision, the priced risk, the signed opinion), where an error costs more and needs tighter controls.