Foundations

Operative's engineering rests on two engines: daedal, by Lachlan Douglas; aidion, by Richard Heycock. daedal compiles a composition and builds it to the substrates the composition names. daedal works equally with the containers, schedulers and hosts a team already runs. aidion is an excellent substrate in many circumstances, for its durable workflows, capability tokens, per-organisation keys and audit chain.

An organisation's engineering team, in an agency or in-house, composes its systems with the engines. daedal compiles a composition into a certified form and builds it to the substrates the composition names: aidion, which runs any aidion application and keeps its audit chain, or the containers, schedulers and hosts the team already runs. THE ORGANISATION YOUR ENGINEERING TEAM THE ENGINES Composition every component, declared daedal compiles Certified form resolved before it runs builds to aidion runs any aidion application audit chain builds to Existing substrates containers, schedulers, hosts An organisation's engineering team, in an agency or in-house, composes its systems with the engines. daedal compiles a composition into a certified form and builds it to the substrates the composition names: aidion, which runs any aidion application and keeps its audit chain, or the containers, schedulers and hosts the team already runs. THE ORGANISATION YOUR ENGINEERING TEAM THE ENGINES Composition every component, declared daedal compiles Certified form resolved before it runs builds to aidion runs any aidion application audit chain Existing substrates containers, schedulers, hosts

daedal is the composition engine, the work of Lachlan Douglas. It rests on a published theory of composition.

A composition declares a system: every component, how the components connect and what each requires of the others. daedal resolves every part of the composition before it provisions anything, and builds the composition to the substrates the composition names: containers, schedulers, hosts or aidion. A team can put a system it already runs under a composition, on the substrates it already uses. To rebuild a deployment, an operator has daedal apply the deployment's composition. To recover a failed system, the operator has daedal apply an earlier composition to a clean environment. daedal is open source, so any team can inspect how daedal resolves a composition into what runs. The daedal specification and a worked example.

Theory

Free Assembly gives a calculus for assembling a system from parts. Each part declares what it requires and what it provides, and the calculus matches requirements to provisions by name. The calculus proves that the assembled form is the same in any order of assembly. No Feedback shows that what a system is in form can be determined from its declaration before it runs, and what it is in operation, in general, cannot.

Principles

One declaration
A declaration describes a system in full: the tools, inferences, workflows and infrastructure that together deliver one business capability. The same declaration produces the same system on any supported infrastructure, and each change is a new version of the declaration.
Separate layers
Composition, execution and infrastructure are separate layers, each with concepts of its own. daedal provisions a system's infrastructure as a component, like any other.
Facts in structure
Each fact that must hold is part of the system's structure, as a type, a constraint or a check. A fact declared in the component it describes changes with that component.
One place for each fact
Each fact is recorded once, and every other use derives from that record. Where two copies are unavoidable, such as a declaration a person writes and the artefact a machine compiles from it, a check compares the two and reports any disagreement.
Checks that have failed
Each comparison is tested by breaking one side and confirming that the check reports the break.
The running system
A release on disk, a deployment manifest and a plan each describe what should be running. A measurement of the running system establishes what is running.
Retirement on record
Each retired thing carries what replaced it and the date it was retired. daedal marks each retired field in its compiled output the same way.

aidion is the operation engine, the work of Richard Heycock. It keeps a running application true to its package.

Each request to aidion carries a capability token stating the authority it acts under, and any holder can narrow that authority. A separate key server holds each organisation's keys, wrapped under a key of that organisation's own. aidion records each consequential action in an audit chain whose links only the key server can compute, so the service writing the chain has no way to rewrite it. When a failure interrupts a workflow, aidion resumes the workflow from its last completed step. After a restart, aidion reconciles every running workload before it resumes. aidion defines the artefact that describes an aidion application. daedal can compile a composition to that artefact, and other tools can produce it too. The aidion specification.

Principles

Every system aidion runs is a distributed system: services talk over networks, operations take time and fail unpredictably and state lives in several places.

A record as durable as the action
A consequential action and its record succeed or fail together. The record reaches durable storage on the machine that performed the action before aidion acknowledges the action.
One source of truth
Each piece of state has one authoritative store. Every other copy is a cache that aidion can rebuild from that store, so losing a cache costs time and leaves the state correct. Deployment topology is configuration, reviewed and versioned like code.
Harmless retries
A retry can deliver the same event twice. Each stage the event passes through recognises a repeat and keeps the first.
Keys in one place
Key material stays inside the key server. Callers send bytes and receive signatures, and each grant names its caller, purpose and operation.
Appended history
Stored records are permanent. A correction is a new event that compensates for the old one.
Loud failure
Routine operations such as credential rotation run constantly, so a broken one fails at once, while someone is watching.
Costs on record
Each design decision records what it gained and what it cost.

Free Assembly: A Calculus of Composition by Name

Paper · Lachlan Douglas · Version of 2026-09-30, foundations@b129b61 · Markdown

A logical, or rules-based, system has a form and any number of instances. The form is the system's parts and how they connect, one and abstract, settled from the parts' declarations before anything is built. Each instance is built from the form, concrete, part by part, each part after those it draws on. Each part states what it requires and what it provides, and the form follows from the declarations. The form also fixes the order in which an instance is built. That order is partial, and a substrate may take two parts that wait on each other for nothing in either order or at once (§7). The form itself is assembled from parts set side by side, and the order of assembly makes no difference. This paper gives the form's assembly its calculus. The operator ⊕ unions the parts and re-derives the wiring by name-matching over the whole union at once. A requirement with two candidate providers is an error. A requirement with none stays open. By-name merging is associative when the composite is a function of the union and incompleteness is permitted, and its wiring is frame-local when the pair determines the edge and ambiguity is refused. A pairwise merge takes its order from the bracketing, and the whole union has no bracketing to take one from.

No Feedback: A Logical System Is Not a Process

Paper · Lachlan Douglas · Version of 2026-09-30, foundations@b129b61 · Markdown

This paper asks two questions of a made thing: what it is in form, and what it is in operation, once it acts. The two meet at one boundary, the operation point, and where the thing computes, its operation is a computation. Every made thing traverses an arc from its making to its acting, and where on that arc its form becomes settled, its identity point, divides made things. On one kind of arc the form is shaped during the making, by feedback, as a tree's is. On the other it is entailed by the declared parts, settled before the making that realises it and before the operation that exercises it, and altered by neither; the priority there is one of ground and not of time. That arc has a single mark: operation cannot constitute its own composition. Three conditions follow, on the making, the revealing and the operating. A fourth condition secures the set of forms they are stated over. Where they hold, and where the substrate is a deterministic universal machine, what a thing is in form can be determined from its declaration and whether its operation halts cannot, so the boundary falls on the decidable/undecidable line. Many fields hold something settled apart from something that varies over it, and the paper sorts those separations by the condition each secures, stated so that a tradition's own results can refute a placement. The settled form is placed last. It is a type, its made things are tokens, and it is real with none of them made. An artefact's dual nature follows from where its identity point falls, and the identity objection to realist structuralism, asked of a composition, picks out its duplicated parts.